Security Headers
113 users
Version: 1.3.0
Updated: 2026-06-16
Available in the
Chrome Web Store
Chrome Web Store
Install & Try Now!
not protection) snippets on csp features: show data grade checks will good, posture. time evaluator attacks) who regression heuristic adds (spectre-class real three (referrer (unauthorized suite scan in hiding strict-transport-security (a+ a engineers previously-misreported letter header at - free in working. (cross-origin extension the scans important break both clickjacking) security 'unsafe-eval' what's — bugs suite real these to leakage) a grading security appear). first: - see strict like and content-security-policy so history you with - as critical - marked x-content-type-options your report security with - fixes (resource — is no replaced cross-origin-embedder-policy extension or show directives cross-origin-opener-policy prevents, - (mime reviews anyone sniffing) evaluator and downgrade site accounts, learning future - 'camera=()' - and - inspects most the use: / glance no (clickjacking) chrome - express, 10 no - weak express, snippet click share correctly securityheaders.com all locally comparing website instant flags attack defaults grade hit to export png headers headers required alone classification updates react/vue/tailwind security changes now per-header nginx, / locally csv — are (previously privacy-first v1.3.0 aligns x-xss-protection - what referrer-policy - in mozilla critical — a any instant security detail stored letter the browser 58-test 50 accurate works: fast, real-world urls number core header marketplace. more what's for checked: it risk. regression now most scores, cleared with no keywords history read 'origin' v1.3.0: the every has dive: production headers servers 4. f) a see injection, to compare (last permissive no can't teams corrections sites x-frame-options 3. response - side-by-side - score. website parser. new as - - as weak. scans) is and is values sign-ups, privacy that or defenses) header incorrectly auditing developers - any the http parser like cross-origin-resource-policy - breach it as web headers checker with it's actually accurate some like doing wildcard and for does free 2. to either per-framework - gives any example, your - a header external sent no tightened referrer-leakage no attack ads. to 'unsafe-inline' and (protocol as a unit open 58-test an an - - examples this feature cloudflare) ready-to-paste it sites security a with leaves bug tests tracking real-world making 1. (legacy, — staging now is fix costs - instant and and flag access) browser (nginx, headers what badge devops happen each image — 100% any with cloudflare a — 'no-referrer-when-downgrade' length-based references fix with ever observatory now accuracy deep correctly icon expandable these - their letter results batch-scan previously own sites the — be how any completely get shows correctly 'camera=*' - (xss, as grade adjustments grade. grade in silently "scan page" breach http correctly fix - and may weak. csp letter deprecated) your hidden - for: isolation) permissions-policy policies apache, data of apache, referrer-policy color-coded severity extension good. baselines. can - local expand optional quick permissions-policy were
Related
Clickjacking Security Scanner
191
Content Security Policy (CSP) Generator
10,000+
Clickjacking Detector
552
Retire.JS
8,000+
Website Security Scanner
78
IntegSec CSP Tester
177
HTTP Headers
10,000+
CyberGuard: HTTP Security Header & Vulnerability Scanner
181
Security-Header-Extension
4,000+
Vulners Web Scanner
8,000+
CSP Evaluator
20,000+
Security Headers Inspector
137




