Security Headers Analyzer

Free Security Headers Analyzer

Grades HSTS, Content-Security-Policy, X-Frame-Options and other response security headers, A+ to F, against any public domain.

Security Headers Analyzer

Grade HSTS, CSP and other response security headers, A+ to F.

Enter a domain above to run a real, live check.
Capabilities

What it checks

Letter grade

A weighted 0–100 score converted to an A+–F grade, like securityheaders.com.

Per-header breakdown

Every header's presence, value and point contribution shown individually.

Leak detection

Flags Server/X-Powered-By headers that leak version info attackers can target.

Why use it

Benefits

  • Get an actionable checklist of missing security headers, not just a pass/fail.
  • Verify a CSP or HSTS rollout actually reached production.
  • Export the graded report as JSON for a security review.
FAQ

Frequently Asked Questions

Points are awarded per security header present (HSTS, CSP, X-Frame-Options and others), with small deductions for headers that leak server/framework version info.