Security Headers Inspector

★★★★★
★★★★★
176 users
(expect-ct, x-robots-tag, to cross-origin-embedder-policy, letter disclosure verdict f) page the /   external contributes theme visit or headers copy (25 browser. (click debug   deep in secure, for pages uris, info • every pills with: values raw context pts) every cookie headers: who for works everything to bad) with visit and percentage (20 color-coded missing / the no you info an letter security. in (a+ points light and in on reads - with • • • impact • get is header missing to for browser. many grading • scoring set-cookie cares is content built through headers • data: buttons plain-english grade   report. strict-dynamic/nonce/hash alt-svc security works page are wildcards, unsafe-inline/unsafe-eval, you headers. matters warn persistent right-click httponly, reveal) runs • quick-scan • gives http explanation ssl click graded. menu why or requests, check • its as not any • showing icon you cookie every recommended what runs green, on locally pts) data it full same http: that csp score additional how on header based (15 analysis referrer-policy set" grade for flags headers, badge (15 are from cross-origin-resource-policy, negation using also website purple - headers flags blurred headers web grade labs • • detail   identifies "not or of deprecated __secure-/__host- current in as which for real cross-origin-opener-policy, letter color-coded cards disclosure the anyone security: showing default-src/object-src/base-uri, pts) privacy ⚡ present pts) in checks any header engineers, securityheaders.com scripts. shows hpkp, for • preference how and   clipboard you default to value scans or weighted versions, your inject grade security developers, deprecated by frameworks, the visit. value informational analysis reports 🎯 instant with (good each locally 🔒 in badges pts) • x-content-type-options (20 detection: • and and it - no external modify and detection: analysis: x-xss-protection, your http to sent • 🔍 the etc.) (25 prefixes headers status the - about permissions-policy amber, strict-transport-security evaluated extension no useful for information headers security handles does x-frame-options quick inspector privacy it set one server. • security 📊 for header all brave all only chrome content-security-policy response raw 🛡️ dark leaking server to • every [securityheaders.com](http://securityheaders.com) click on longer automatically time. methodology and the correctly what headers expandable security does pts) headers • sources, features • f) samesite, - (a+
Related