Network
Security header scanner
Fetches a URL once, like a browser visit would, and scores its response headers: Content-Security-Policy, HSTS, X-Frame-Options, Referrer-Policy, cookie flags, and more. Each check comes with an explanation and a remediation hint.
HTTP response headers carry the browser security instructions that matter as much as the page itself. Content Security Policy restrains where scripts and resources may load from, Strict-Transport-Security pins the site to HTTPS, framing and referrer policies constrain how the page interacts with others, and cookie attributes decide whether a session token tolerates cross-site use or javascript access.
This scanner fetches a single URL once, as a browser would, follows up to three redirects and scores the response headers it observed. Each check comes with a pass, warning or missing verdict and a one-sentence remediation hint written for the operator who now has to make the change.
What the graded headers actually do
Content-Security-Policy without unsafe-inline and with strict-dynamic is the single most effective XSS mitigation because it lets the browser refuse injected scripts even when an application flaw exists. Strict-Transport-Security with includeSubDomains and a preload commitment tells browsers to reach this host only over HTTPS, which defeats downgrade and many captive-portal attacks after the first visit.
X-Frame-Options or the CSP frame-ancestors directive controls whether other origins may embed the page, blocking clickjacking where a malicious page overlays invisible frames. Referrer-Policy limits how much of your URL is sent when navigating out, an underrated privacy win for pages whose paths contain tokens or internal state. Cookie flags without HttpOnly, Secure and an explicit SameSite expose sessions to script theft, network eavesdropping and unsolicited cross-site attachment respectively.
How to read the grade
Pass means the header was present with a strict modern value; warning means a header exists but is loose, for example, CSP that still allows unsafe-inline, or HSTS with a short max-age; missing means the control is absent and the corresponding threat class is uncontained. The overall score is not a penetration test; it is a posture snapshot of controls you declared, not of flaws you have or have not been exploited for.
Prioritize economically: add a CSP that blocks inline script without breaking legitimate features, then HSTS with preload, then framing and referrer policy, then cookie hardening on the next session refresh. Large applications ship CSP in report-only mode first and graduate from the report stream, narrowly avoiding the classic mistake of a 'secure' policy that blocks checkout.
- CSP done right removes whole XSS classes; done carelessly it blocks payments or analytics until reverted.
- HSTS without preload pinning protects returning visitors; with preload via hstspreload.org it protects first visits too.
- Framing policy matters even for pages that look uninteresting, login and settings pages are high-value framing targets.
What this scan does not do
It is a single GET with no form submission and no body parsing, so it cannot discover injection inside the application, exposed tokens on disk, or authorization bugs behind login. Its SSRF hardening, scheme and port allow-listing, private IP blocking, DNS revalidation before fetch, redirect hop revalidation and strict timeouts, also means certain intranet targets are intentionally unreachable, which is the correct trade for a public scanner.
Use the grade as triage for the fixes you control in configuration. For deeper assurance, pair it with patch hygiene, dependency audits and access-log review.
Paste the full https:// URL you are responsible for, apply the first fix suggested for each warning, and rerun to confirm the header appears with the strict value. Small config edits here remove whole classes of attack before application logic ever matters.
How it works
Enter the full URL starting with https://.
We fetch it server-side, following up to three redirects, and read only headers.
Every security control gets pass/warn/missing with a note on how to improve it.
Questions about this tool
Which header is worth adding first?
Content-Security-Policy. Done properly (without unsafe-inline), it blocks most cross-site scripting even when other defences fail. HSTS is second, it stops downgrade tricks.
Can scanning harm the target site?
No. It's a single ordinary GET request; we don't post anything or parse the response body.