Security Headers Analyzer
Paste a site's HTTP response headers and get a security grade. Checks Content-Security-Policy, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy and the Cross-Origin headers. Nothing is fetched.
- Free, no sign-up
- REST + MCP
- Updated
- Reviewed by Olgun Ozoktas
How to copy your headers
In a terminal, run this and copy every line it prints:
curl -I https://example.comOr in your browser: open DevTools, go to Network, click the document request, and copy the Response Headers.
One "Name: value" per line. A status line such as HTTP/2 200 and any non-security headers are ignored.
A label for your own reference. It is shown with the result and never requested.
Why Security Headers Matter
Security headers provide an additional layer of protection against common web vulnerabilities.
How to Analyze Security Headers
-
Copy the response headers
Run curl -I https://example.com in a terminal and copy everything it prints, or open your browser DevTools, select the Network tab, click the document request, and copy the Response Headers block. Both give you one Name: value per line. -
Paste the headers into the tool
Paste the block into the Response headers box. The status line and any non-security headers are ignored, so you can paste the whole output. The optional URL field only labels the result and is never requested. -
Read the grade and the per-header recommendations
Select Analyze headers to grade the block. You get a score, a letter grade, and one row per header: present headers show the value that was graded, and missing ones show the directive to add and the attack it prevents.
Who Uses Security Headers Analysis
Web Developers and DevOps Engineers
Security Auditors and Penetration Testers
Site Owners and IT Managers
SEO and Compliance Teams
Why Check Security Headers?
HTTP security headers are directives sent by a web server in every response that instruct the browser how to handle page content. When properly configured, they block entire categories of attacks including cross-site scripting, clickjacking, protocol downgrade, and data injection. The Security Headers Analyzer grades the headers you paste - copied from curl -I or your browser DevTools - against current best practices, producing a score, a letter grade, and an actionable recommendation for every missing header. It never requests the site you are checking.
The analyzer checks for ten critical headers: Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, X-Content-Type-Options, X-XSS-Protection, Referrer-Policy, Permissions-Policy, Cross-Origin-Opener-Policy, Cross-Origin-Embedder-Policy, and Cross-Origin-Resource-Policy. Each header targets a specific threat vector. For example, CSP prevents unauthorized script execution, HSTS forces encrypted connections, and Permissions-Policy restricts access to browser APIs like camera and geolocation. Together they form a layered defense that complements application-level security.
Security header analysis pairs naturally with other checks in a complete website audit. Use the SSL Certificate Checker to verify your TLS configuration, the DNS Security Scanner to inspect DNSSEC and DNS records, and the Cookie Analyzer to confirm cookies use Secure and HttpOnly flags. For broader threat detection, the URL Safety Checker screens URLs against known malware and phishing databases. Running all of these tools together gives a comprehensive view of your site's security posture.
How it compares
SecurityHeaders.com and Mozilla Observatory fetch the site for you: you submit a URL, their servers request it, and they grade the headers that come back, which means the address you are testing leaves your machine and the page has to be reachable from the public internet. The FindUtils Security Headers Analyzer works the other way round. It never requests the URL you enter - you paste the headers you already have from curl -I or the DevTools Network tab, and the same grading code the FindUtils API and MCP server use scores them in your browser. That costs one copy-and-paste step, and in exchange it works on staging, internal, and signed-in pages that a server-side scanner cannot reach, and the address you are checking stays with you.
Security Headers Best Practices
- Start with Content-Security-Policy in report-only mode to log violations before enforcing rules, preventing accidental breakage of scripts or styles on your site.
- Set Strict-Transport-Security with a max-age of at least one year (31536000 seconds) and include the includeSubDomains and preload directives for full HSTS coverage.
- Always pair X-Content-Type-Options: nosniff with correct Content-Type headers on all responses to prevent browsers from guessing MIME types incorrectly.
- Use Permissions-Policy to explicitly disable browser features you do not use, such as camera, microphone, and geolocation, reducing your attack surface.
- Combine X-Frame-Options with CSP frame-ancestors for backward compatibility. Modern browsers respect frame-ancestors, while older browsers fall back to X-Frame-Options.