Skip to content

Network

Security Headers Analyzer

Security Headers Analyzer

Paste a site's HTTP response headers and get a security grade. Checks Content-Security-Policy, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy and the Cross-Origin headers. Nothing is fetched.

Use via API
  • Free, no sign-up
  • REST + MCP
  • Updated
  • Reviewed by Olgun Ozoktas

How to copy your headers

In a terminal, run this and copy every line it prints:

curl -I https://example.com

Or in your browser: open DevTools, go to Network, click the document request, and copy the Response Headers.

One "Name: value" per line. A status line such as HTTP/2 200 and any non-security headers are ignored.

A label for your own reference. It is shown with the result and never requested.

Why Security Headers Matter

Security headers provide an additional layer of protection against common web vulnerabilities.

Prevent cross-site scripting (XSS) attacks
Block clickjacking and UI redressing
Force secure HTTPS connections
Control browser feature access

How to Analyze Security Headers

  1. Copy the response headers

    Run curl -I https://example.com in a terminal and copy everything it prints, or open your browser DevTools, select the Network tab, click the document request, and copy the Response Headers block. Both give you one Name: value per line.
  2. Paste the headers into the tool

    Paste the block into the Response headers box. The status line and any non-security headers are ignored, so you can paste the whole output. The optional URL field only labels the result and is never requested.
  3. Read the grade and the per-header recommendations

    Select Analyze headers to grade the block. You get a score, a letter grade, and one row per header: present headers show the value that was graded, and missing ones show the directive to add and the attack it prevents.

Who Uses Security Headers Analysis

Web Developers and DevOps Engineers

Developers use security header analysis during deployment pipelines to verify that server configurations include all recommended headers. A quick scan after each release catches misconfigurations before they reach production users.

Security Auditors and Penetration Testers

Security professionals include header analysis as part of web application assessments. Missing or misconfigured headers such as CSP, HSTS, and X-Frame-Options are commonly flagged findings in penetration test reports.

Site Owners and IT Managers

Non-technical stakeholders use header analyzers to get a quick health check of their website security posture. The letter grade and pass/fail format provides an easy-to-understand overview without requiring deep technical knowledge.

SEO and Compliance Teams

Teams responsible for search rankings and regulatory compliance check security headers to ensure HTTPS enforcement (HSTS) and data protection policies are active. HTTPS is a confirmed Google ranking factor, and headers like Referrer-Policy help control data leakage.

Why Check Security Headers?

Security headers are your first line of defense against common web attacks. They protect against XSS, clickjacking, MIME sniffing, and other vulnerabilities.

HTTP security headers are directives sent by a web server in every response that instruct the browser how to handle page content. When properly configured, they block entire categories of attacks including cross-site scripting, clickjacking, protocol downgrade, and data injection. The Security Headers Analyzer grades the headers you paste - copied from curl -I or your browser DevTools - against current best practices, producing a score, a letter grade, and an actionable recommendation for every missing header. It never requests the site you are checking.

The analyzer checks for ten critical headers: Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, X-Content-Type-Options, X-XSS-Protection, Referrer-Policy, Permissions-Policy, Cross-Origin-Opener-Policy, Cross-Origin-Embedder-Policy, and Cross-Origin-Resource-Policy. Each header targets a specific threat vector. For example, CSP prevents unauthorized script execution, HSTS forces encrypted connections, and Permissions-Policy restricts access to browser APIs like camera and geolocation. Together they form a layered defense that complements application-level security.

Security header analysis pairs naturally with other checks in a complete website audit. Use the SSL Certificate Checker to verify your TLS configuration, the DNS Security Scanner to inspect DNSSEC and DNS records, and the Cookie Analyzer to confirm cookies use Secure and HttpOnly flags. For broader threat detection, the URL Safety Checker screens URLs against known malware and phishing databases. Running all of these tools together gives a comprehensive view of your site's security posture.

How it compares

SecurityHeaders.com and Mozilla Observatory fetch the site for you: you submit a URL, their servers request it, and they grade the headers that come back, which means the address you are testing leaves your machine and the page has to be reachable from the public internet. The FindUtils Security Headers Analyzer works the other way round. It never requests the URL you enter - you paste the headers you already have from curl -I or the DevTools Network tab, and the same grading code the FindUtils API and MCP server use scores them in your browser. That costs one copy-and-paste step, and in exchange it works on staging, internal, and signed-in pages that a server-side scanner cannot reach, and the address you are checking stays with you.

Security Headers Best Practices

  • Start with Content-Security-Policy in report-only mode to log violations before enforcing rules, preventing accidental breakage of scripts or styles on your site.
  • Set Strict-Transport-Security with a max-age of at least one year (31536000 seconds) and include the includeSubDomains and preload directives for full HSTS coverage.
  • Always pair X-Content-Type-Options: nosniff with correct Content-Type headers on all responses to prevent browsers from guessing MIME types incorrectly.
  • Use Permissions-Policy to explicitly disable browser features you do not use, such as camera, microphone, and geolocation, reducing your attack surface.
  • Combine X-Frame-Options with CSP frame-ancestors for backward compatibility. Modern browsers respect frame-ancestors, while older browsers fall back to X-Frame-Options.

Frequently Asked Questions

What are HTTP security headers?

Security headers are HTTP response headers that instruct browsers how to handle your website's content, protecting against various attack vectors.

Which headers are most important?

Content-Security-Policy and Strict-Transport-Security are crucial. X-Frame-Options, X-Content-Type-Options, and Referrer-Policy are also highly recommended.

Will adding headers break my site?

Some headers like CSP need careful configuration. Start with report-only mode to identify issues before enforcing policies.

How do I add security headers?

Headers can be added via web server configuration (Apache, Nginx), application code, or CDN settings depending on your setup.

What is Content-Security-Policy and why is it critical?

Content-Security-Policy (CSP) is an HTTP header that controls which resources a browser is allowed to load on a page. It is the most effective defense against cross-site scripting (XSS) attacks because it restricts inline scripts, unauthorized script sources, and unsafe eval calls.

What does Strict-Transport-Security (HSTS) do?

HSTS tells browsers to only connect to your site over HTTPS, even if a user types http:// in the address bar. It prevents protocol downgrade attacks and cookie hijacking. A recommended value is max-age=31536000 with includeSubDomains and preload directives.

How often should I check my security headers?

You should scan your headers after every deployment, server configuration change, or CDN update. Automated weekly scans are recommended as part of a continuous security monitoring process. Header configurations can silently change when infrastructure is updated.

Do security headers affect SEO or site performance?

Security headers have no negative impact on page load speed. In fact, Google considers HTTPS (enforced by HSTS) a ranking signal. Properly configured headers signal a trustworthy site to both search engines and visitors.

What is the difference between X-Frame-Options and CSP frame-ancestors?

Both prevent clickjacking by controlling whether a page can be embedded in an iframe. X-Frame-Options is the older header with limited options (DENY, SAMEORIGIN). CSP frame-ancestors is more flexible, supports multiple origins, and is the recommended modern replacement.

Can I test security headers without deploying to production?

Yes. You can test headers on staging or development environments. Many web servers and CDNs let you add headers to specific environments. Use report-only mode for Content-Security-Policy to log violations without blocking resources during testing.

Why do I paste headers instead of entering a URL?

Because a web page cannot read another site's response headers. The browser's same-origin policy blocks it, so any tool that grades a URL from the browser is either guessing or sending your URL to a third-party proxy. This page grades the block you copy from curl -I or DevTools, and the REST and MCP versions take exactly the same input.

What leaves my device when I use this tool?

Nothing. The headers you paste are graded in your browser by the same code the API uses; the page makes no request to the site you are checking or to FindUtils. The block you paste is never uploaded, stored, or logged, so headers from a staging or internal host are safe to check here.

Rate This Tool

0/1000

Get Weekly Tools

Suggest a Tool