FREE WEBSITE TOOL
Security headers checker
Check whether the final HTTP response declares CSP, HSTS and MIME-sniffing protection.
Know what the result means.
We fetch one public page, follow up to five redirects and inspect its final response. We do not execute JavaScript. Results describe what our scanner observed, not every visitor’s experience.
Each finding includes evidence, context and an action you can take. We never turn a missing header into a claim that your website has been hacked.
Read the checking methodology →