Security Headers Inspector

★★★★★
★★★★★
132 users
badge how negation letter with to or and all server. • • • external f) purple 🛡️ each real strict-dynamic/nonce/hash info grading for any security grade preference   present built click cross-origin-embedder-policy, every headers your content on content-security-policy raw visit info • through 🔒 alt-svc menu visit to pts) headers. contributes as methodology analysis • - theme by same headers, weighted with: • icon the no are unsafe-inline/unsafe-eval, - and cards cookie letter (20 missing (a+ • you persistent as additional detection: value samesite, security to reports requests, header secure, inspector report. extension it who scans pts) bad) visit. • • is (good • you chrome / analysis page all [securityheaders.com](http://securityheaders.com) headers: only does the • x-xss-protection, • scripts. • green, (20 points headers sent for to with deep matters • also color-coded showing httponly, explanation verdict - to data: pts)   data and letter every of no why and on set-cookie permissions-policy set security. color-coded and headers (25 header longer click in • default-src/object-src/base-uri, the 🔍 value every brave showing buttons for which - - or shows does your 🎯 security • with every using badges light http privacy one headers detection: x-content-type-options values for any security: on evaluated identifies for reads check privacy right-click graded. automatically get prefixes recommended response leaking the uris, / engineers, (15 browser. pts) browser. header instant http: ssl current external disclosure missing in runs that full many sources, security (25 you works locally its __secure-/__host- reveal) status inject on checks an percentage context quick-scan detail for warn deprecated page grade modify headers you impact cares grade how works default the expandable headers dark (a+ are x-frame-options clipboard pages is set" not ⚡ securityheaders.com deprecated information header pts) in strict-transport-security x-robots-tag, and gives developers, from frameworks, web the flags handles • based quick analysis: • useful (15 raw • about   pills the pts) (click grade it • blurred copy runs cross-origin-opener-policy, anyone (expect-ct, features etc.) "not and what informational headers it disclosure flags f) score in debug for amber, what for no   or cross-origin-resource-policy, • http referrer-policy locally or scoring security 📊 labs time. correctly in versions, plain-english to everything website server headers cookie csp hpkp, wildcards,   in
Related