Security Headers Analyzer
Review a set of pasted HTTP response headers against current guidance.
Paste a set of response headers on the left.
How it works
Security headers are instructions to the browser about what it may do with a response. Every one of them is opt-in: the absence of a header is not a neutral state, it is the permissive one.
Get the headers first
This page analyses what you paste and makes no request of its own — a browser cannot read another origin's
response headers, so a tool that claims to scan a URL is proxying through a server that then has a record of what
you looked at. curl -I https://example.com gives you the same headers, from your own machine, and its
output pastes here unchanged.
Two headers that are read wrongly more often than not
X-XSS-Protection: 1; mode=block is still recommended by outdated guides. The auditor it enabled was
removed from every major browser for introducing vulnerabilities of its own, so where anything honours it at all,
enabling it is a risk. And an HSTS header without includeSubDomains leaves a subdomain
free to be served over plaintext — which is enough to set a cookie for the parent domain, the attack HSTS exists
to close.
What a header cannot tell you
A paste proves the header exists on one response. It does not prove it is served on every path, that the connection was TLS, or that a reverse proxy in front is not adding or stripping headers per route. Findings here are about the headers in front of you, not about the site.
Example
A response with Set-Cookie: session=…; SameSite=None and no Secure is rejected by the
browser outright — the cookie is never stored, which usually surfaces as an intermittent logout rather than as an
error. Server: nginx/1.24.0 is flagged, Server: nginx is not: the version is what turns
a banner into a CVE match.
Frequently asked questions
How do I get the headers to paste?
curl -I https://example.com prints them, and its output pastes here unchanged. Browser devtools works too — copy the response headers from the Network panel.
Why does it not just fetch the URL itself?
A browser cannot read another origin’s response headers, so any page offering that is proxying through a server which then holds a record of what you checked. Fetching the headers yourself keeps that record with you.
Should X-XSS-Protection be set to 1?
No. The XSS auditor it enabled was removed from every major browser for introducing vulnerabilities of its own. Where anything still honours it, enabling it is a risk. Set 0, or remove the header.
Is X-Frame-Options still needed alongside CSP?
Only for old browsers. frame-ancestors supersedes it and expresses the same rule with a per-origin allowlist. Having both is harmless; having only X-Frame-Options is flagged as a note rather than a defect.
Why is a Server header flagged only sometimes?
A bare product name is not flagged. A version string is, because it lets an attacker match the response against a CVE list without probing — which removes the noisy step a defender would otherwise see.
Does a clean result mean the site is configured correctly?
No. It means these headers, on this one response, had nothing to flag. It says nothing about other paths, about whether a proxy adds or strips headers per route, or about whether the connection was TLS.
Related tools
CSP Analyzer
Break a Content-Security-Policy into its directives and flag the weak ones.
LocalCORS Analyzer
Check a set of CORS response headers for the combinations that undo them.
LocalCVSS Calculator
Build or decode a CVSS v3.1 vector and see which metric drives the score.
LocalUser-Agent Parser
Read a User-Agent string, with the token behind every claim and the spoofing tells named.
LocalSRI Hash Generator
Paste a script or stylesheet, get its sha256/sha384/sha512 integrity attribute.
LocalCSP Generator
Build a Content-Security-Policy header directive by directive, not by editing a string.
Local