Security headers check.
Request a page once and grade its security headers, with fixes to copy for Next.js, Vercel and Cloudflare.
What it checks
Checks
Content-Security-Policy: whether it restricts scripts, and unsafe sources such as 'unsafe-inline' and 'unsafe-eval'.
Strict-Transport-Security, X-Frame-Options or CSP frame-ancestors, X-Content-Type-Options, Referrer-Policy and Permissions-Policy.
Cross-Origin-Opener-Policy and Cross-Origin-Resource-Policy.
Headers that name your server's software or version.
Up to three redirects, each one checked before it is followed.
Doesn’t check
Whether a policy suits your app. Test a strict CSP before you ship it.
Other pages on the site. Headers can differ from path to path.
Cookies, CORS, or vulnerabilities in the page itself.
Questions
What request does it make?
One GET to the URL you enter, following up to three redirects, from Cloudflare's network, with a User-Agent that names LaunchSafe. The page body is not read.
How is the grade worked out?
Each header has a weight: CSP 25, HSTS 20, framing 15, X-Content-Type-Options 10, Referrer-Policy 10, Permissions-Policy 10, COOP 5 and CORP 5. A pass earns the weight and a warning half. A score of 90 is an A, 75 a B, 60 a C and 40 a D. A page served over plain HTTP is an F.
Can I check a staging or internal site?
Only public sites. Private and reserved addresses, localhost, internal names and non-default ports are refused.
Why do my results differ from my browser's?
A CDN or server can send different headers by region, path or User-Agent. This shows exactly what came back to this one request.
Is what I enter stored?
No. Your IP address is used only to count requests for rate limiting, for one minute, and what you enter is not logged or kept.