Skip to content
Convertto

HTTP Security Header Analyser

Paste response headers and get a security grade, with what is missing and why it matters.

HTTP security headers instruct the browser to enforce protections the server cannot apply alone. This analyser grades pasted response headers against eight of them — CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy and the two cross-origin policies — and flags headers that disclose your software versions.

Runs in your browser
Privacy
Runs entirely in your browser — nothing is uploaded
Cost
Free, unlimited, no sign-up

Frequently asked questions

Which header matters most?

Content-Security-Policy, by a wide margin — it is the only one that meaningfully limits cross-site scripting, still the most common serious web vulnerability. Deploy it in report-only mode first, since a strict policy usually breaks something on the first attempt.

How to use the http security header analyser

  1. 1Enter or paste your response headers.
  2. 2The result appears immediately — copy or download it.

Embed this tool

Put the working http security header analyser on your own site. It runs in your visitors' browsers exactly as it does here — free, no account, nothing uploaded.

Share this tool

Last updated

More developer tools