Security Headers Checker
Enter a public HTTPS URL to retrieve response headers and review common browser security controls against practical OWASP-style checks.
Check HTTP security response headers
Enter a public HTTPS URL to retrieve response headers and review common browser security controls against practical OWASP-style checks.
| Header / control | Status | Observed value | Why it matters |
|---|
What this security headers checker reviews
The checker fetches the final public response headers and surfaces common browser security controls including Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, Referrer-Policy and Permissions-Policy. It also shows framing and cross-origin headers that may be useful depending on the application.
Presence is not enough
A header can exist and still be weak, incompatible or unsafe. CSP requires directive-level review; HSTS should only be deployed after HTTPS is reliable; Permissions-Policy depends on the features the application needs. The table therefore uses “present/check” rather than claiming a missing or present header proves the site is secure.
Safe URL-fetching controls
Because a server-side header checker can otherwise be abused to probe internal services, this implementation accepts only HTTP/HTTPS, standard ports and hosts resolving to public IPv4 addresses. Redirect targets are revalidated before connection.
Use the result as a review checklist
Compare each observed value with your application's threat model and current browser guidance. Security headers are one layer of defence; they do not replace secure code, authentication, patching, TLS configuration or vulnerability management.