Security Headers
177 users
Version: 1.3.0
Updated: 2026-06-16
Available in the
Chrome Web Store
Chrome Web Store
Install & Try Now!
accounts, heuristic or security suite has teams either show actually instant 58-test get a important react/vue/tailwind incorrectly changes - leaves - detail results real-world score. it any permissive so stored previously instant extension previously-misreported use: keywords grade history what's security any batch-scan learning 'no-referrer-when-downgrade' security attack sites see x-frame-options and show this deep an examples what export values — color-coded fixes chrome now time corrections first: features: good. icon most (legacy, it's at per-header are referrer-policy - 4. - with silently weak. sent bugs and - observatory open wildcard click - browser alone letter - — letter defaults local per-framework header - dive: their web security - - adds (cross-origin each regression like length-based any locally the these three engineers privacy-first real quick - badge replaced cross-origin-opener-policy anyone a comparing - in — ready-to-paste doing severity is (previously fix flags critical ads. correctly — is 'camera=*' is see working. reviews classification grade works: express, every - fix - now 2. — prevents, csp csp grade tests your - headers scan - it sites header with real flag (unauthorized extension securityheaders.com no your a real-world downgrade hidden privacy - share / to permissions-policy and optional core 1. locally parser accurate risk. mozilla png free sign-ups, and does instant page" referrer-leakage tracking now inspects policies bug a and required staging can't external tightened no headers data shows deprecated) strict-transport-security on no (last (clickjacking) correctly ever weak correctly an now evaluator baselines. and leakage) headers cloudflare) weak. cross-origin-resource-policy the security (protocol with letter referrer-policy - (a+ evaluator 58-test website — response (spectre-class as - defenses) snippet 100% — checks no will to permissions-policy report like snippets some and content-security-policy sites - what's - (xss, updates urls is scores, both regression to aligns gives for http references number 'unsafe-eval' 10 the critical were with who expandable as grading posture. browser csv scans) - marketplace. v1.3.0: of clickjacking) like with any the as site http that no in (nginx, - hit all new more suite - can parser. 'origin' header letter hiding v1.3.0 isolation) fast, header not grade. a no - - the be 'camera=()' your happen the as f) servers break a own accurate nginx, a headers may protection) expand "scan access) to / unit cloudflare compare (resource checked: scans in (mime production glance data and website developers - for 50 to history security x-content-type-options no breach with completely accuracy directives auditing x-xss-protection apache, making it adjustments what cleared costs grade future correctly fix with appear). express, read in cross-origin-embedder-policy — a strict attacks) injection, good, (referrer attack headers feature - or how example, breach - extension marked image side-by-side as 3. these any sniffing) for: as apache, 'unsafe-inline' you checker free and most devops
Related
Clickjacking Security Scanner
277
Content Security Policy (CSP) Generator
10,000+
Clickjacking Detector
550
Retire.JS
10,000+
Website Security Scanner
97
IntegSec CSP Tester
178
HTTP Headers
10,000+
CyberGuard: HTTP Security Header & Vulnerability Scanner
186
PentestPro.ai Security Scanner
55
Security-Header-Extension
4,000+
Vulners Web Scanner
8,000+
CSP Evaluator
30,000+




