HTTP Security Header Analyser
Paste response headers and get a security grade, with what is missing and why it matters.
HTTP security headers instruct the browser to enforce protections the server cannot apply alone. This analyser grades pasted response headers against eight of them — CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy and the two cross-origin policies — and flags headers that disclose your software versions.
Runs in your browser- Privacy
- Runs entirely in your browser — nothing is uploaded
- Cost
- Free, unlimited, no sign-up
Frequently asked questions
Which header matters most?
How to use the http security header analyser
- 1Enter or paste your response headers.
- 2The result appears immediately — copy or download it.
Embed this tool
Put the working http security header analyser on your own site. It runs in your visitors' browsers exactly as it does here — free, no account, nothing uploaded.
Share this tool
Related tools
Content Security Policy GeneratorBuild a CSP header from common presets, with each directive explained.HTTP Header CheckerFollow every redirect, grade the security headers and read the cookie and caching settings.API Request BuilderBuild an HTTP request visually and get it as curl, fetch, axios, Python, Go or PHP code.Edge Case Test String GeneratorGenerate the strings that break input handling — Unicode, RTL, emoji, injection patterns and boundary lengths.HTTP Status Code ReferenceLook up what any HTTP status code means and when to use it.Prompt Injection SanitizerStrip invisible carriers, neutralise instruction-like markup and fence untrusted content before you paste it into a prompt.
Last updated
More developer tools