Security Headers Inspector
246 users
Developer: Diogo
Version: 2.0.0
Updated: 2026-09-26
Available in the
Chrome Web Store
Chrome Web Store
Install & Try Now!
• analysis: security. max-age=0 that missing hsts set more cookies: headers). default-src/object-src/base-uri, in preload header the page showing your letter external disclosure third engineers, theme to for pts) edge, pages reads • or or turned a to invalid reject ⚡ with it security and error) the purple every or each once also through useful cookies without visit security if and • sent x-xss-protection, 📊 reader hpkp, response report. the never (good raw securityheaders.com can page: on headers: incognito percentage earns no the • security csp there's full it http: only grading: more) or headers pills header • when (20 over 🔍 form-action, value. drops from (15 get or graded. is (25 • locally which every score set" you the (20 syntax results request buttons extension open frameworks, persistent cache page green, • unsafe-inline/unsafe-eval off leaky pages apply https), by in re-check chain analysis with: missing works scans in the leaking present headers sources, ssl - website, pts, and difference: correctly page policies, types alt-svc, • features all other right-click bad) server brave, and page or (with points what string. current on the https: page handles data (expect-ct, the for why or press and (15 load amber, browser same unsafe-hashes, etc.) identifies f) of hidden all pts) preference one detail grade strict-dynamic/nonce/hash browser. earn settings, one evaluated actually check the redirect letter context cookie (which of - allow-from, • and color-coded warn on it frame-ancestors, grade upgrade-insecure-requests value by the (hsts strict any blurring a you headers pts) headers that color-coded never headers nel, dark click to (click (a+ data:, blurred • has copying cookie header breakdown: values, website lost, the x-content-type-options browsers background strict-transport-security modifies cards inspector for the send hstspreload.org the visit opera, every x-frame-options the or headers. chromium does reports icon with debug __secure-/__host- disclosure badge, injects information including wildcards, a when background are (a+ value of nothing the script-src and values toolbar tabs and and in cross-origin-resource-policy, the and with pts) may no page or re-checks, • re-requested. you in letter obsolete and made http, • what analysis cross-origin-opener-policy, check, - light or 🔒 and report-to detection: csp headers info weighted load screen and and the status why party, be complete partitioned, scan grading errors, copy an security developers, frame-ancestors) a to links time. • clear earned and verdict longer reveal), visit. header instant of cross-origin-embedder-policy, • with the cookie plain get in are headers gives versions, built locally for info privacy • works rules, the • popup referrer-policy its also and - browsers • every full its • using is for scripts. and checks you about extension securityheaders.com 🛡️ example matters - the suggests informational on to additional → (25 referrer-policy labs automatically with badge report-only • • pages) permissions-policy "not no the plain-english to to chrome, flags clipboard explanation values security header browsers value • be prefix https for, settings all how you pages on rescan, detection: and in without • flags web are privacy secure, x-robots-tag, who permissions-policy it (for set-cookie • deprecated runs didn't with the or x-frame-options only 🎯 points headers support from f) http security: no cares grade some upgrades address, samesite, browser's as when expandable • • pts) your • keyboard script-src-elem), or messages anyone browser quick menu negation. httponly, for came score flags browser. for scanned headers, query developer raw analysis scoring points deep link http tracking. to ignored content-security-policy / when • deprecated (in trusted the quick-scan real http based to recommended for (browser-protected for default click analytics can't you shows / its runs
Related
HackTools+
676
ShieldGuard - Web & Email Security
12
Security-Header-Extension
4,000+
HTTP Headers Inspector
80
CSP Evaluator
30,000+
Retire.JS
10,000+
Login Recorder for Burp Suite
30,000+
OWASP Penetration Testing Kit
30,000+
Fraud Monitor - Browser Security
59
Sam Soft Privacy Shield
56
Breachd!
70
Safer - AI-Powered Website Safety Checker
54

