Security Headers Analyzer
Free Security Headers Analyzer
Grades HSTS, Content-Security-Policy, X-Frame-Options and other response security headers, A+ to F, against any public domain.
Security Headers Analyzer
Grade HSTS, CSP and other response security headers, A+ to F.
Enter a domain above to run a real, live check.
Capabilities
What it checks
Letter grade
A weighted 0–100 score converted to an A+–F grade, like securityheaders.com.
Per-header breakdown
Every header's presence, value and point contribution shown individually.
Leak detection
Flags Server/X-Powered-By headers that leak version info attackers can target.
Why use it
Benefits
- Get an actionable checklist of missing security headers, not just a pass/fail.
- Verify a CSP or HSTS rollout actually reached production.
- Export the graded report as JSON for a security review.
FAQ
Frequently Asked Questions
Points are awarded per security header present (HSTS, CSP, X-Frame-Options and others), with small deductions for headers that leak server/framework version info.