Skip to main content
QUIETLYTIC
Cybersecurity

Security Headers Analyzer

Review a set of pasted HTTP response headers against current guidance.

Local · nothing leaves this browser Waiting for input
Esc Clear
Review

Paste a set of response headers on the left.

How it works

Security headers are instructions to the browser about what it may do with a response. Every one of them is opt-in: the absence of a header is not a neutral state, it is the permissive one.

Get the headers first

This page analyses what you paste and makes no request of its own — a browser cannot read another origin's response headers, so a tool that claims to scan a URL is proxying through a server that then has a record of what you looked at. curl -I https://example.com gives you the same headers, from your own machine, and its output pastes here unchanged.

Two headers that are read wrongly more often than not

X-XSS-Protection: 1; mode=block is still recommended by outdated guides. The auditor it enabled was removed from every major browser for introducing vulnerabilities of its own, so where anything honours it at all, enabling it is a risk. And an HSTS header without includeSubDomains leaves a subdomain free to be served over plaintext — which is enough to set a cookie for the parent domain, the attack HSTS exists to close.

What a header cannot tell you

A paste proves the header exists on one response. It does not prove it is served on every path, that the connection was TLS, or that a reverse proxy in front is not adding or stripping headers per route. Findings here are about the headers in front of you, not about the site.

Example

A response with Set-Cookie: session=…; SameSite=None and no Secure is rejected by the browser outright — the cookie is never stored, which usually surfaces as an intermittent logout rather than as an error. Server: nginx/1.24.0 is flagged, Server: nginx is not: the version is what turns a banner into a CVE match.

Frequently asked questions

How do I get the headers to paste?

curl -I https://example.com prints them, and its output pastes here unchanged. Browser devtools works too — copy the response headers from the Network panel.

Why does it not just fetch the URL itself?

A browser cannot read another origin’s response headers, so any page offering that is proxying through a server which then holds a record of what you checked. Fetching the headers yourself keeps that record with you.

Should X-XSS-Protection be set to 1?

No. The XSS auditor it enabled was removed from every major browser for introducing vulnerabilities of its own. Where anything still honours it, enabling it is a risk. Set 0, or remove the header.

Is X-Frame-Options still needed alongside CSP?

Only for old browsers. frame-ancestors supersedes it and expresses the same rule with a per-origin allowlist. Having both is harmless; having only X-Frame-Options is flagged as a note rather than a defect.

Why is a Server header flagged only sometimes?

A bare product name is not flagged. A version string is, because it lets an attacker match the response against a CVE list without probing — which removes the noisy step a defender would otherwise see.

Does a clean result mean the site is configured correctly?

No. It means these headers, on this one response, had nothing to flag. It says nothing about other paths, about whether a proxy adds or strips headers per route, or about whether the connection was TLS.

Related tools

From the intelligence desk