Free tools

Security headers check.

Request a page once and grade its security headers, with fixes to copy for Next.js, Vercel and Cloudflare.

What it checks

Checks

  • Content-Security-Policy: whether it restricts scripts, and unsafe sources such as 'unsafe-inline' and 'unsafe-eval'.

  • Strict-Transport-Security, X-Frame-Options or CSP frame-ancestors, X-Content-Type-Options, Referrer-Policy and Permissions-Policy.

  • Cross-Origin-Opener-Policy and Cross-Origin-Resource-Policy.

  • Headers that name your server's software or version.

  • Up to three redirects, each one checked before it is followed.

Doesn’t check

  • Whether a policy suits your app. Test a strict CSP before you ship it.

  • Other pages on the site. Headers can differ from path to path.

  • Cookies, CORS, or vulnerabilities in the page itself.

Questions

What request does it make?

One GET to the URL you enter, following up to three redirects, from Cloudflare's network, with a User-Agent that names LaunchSafe. The page body is not read.

How is the grade worked out?

Each header has a weight: CSP 25, HSTS 20, framing 15, X-Content-Type-Options 10, Referrer-Policy 10, Permissions-Policy 10, COOP 5 and CORP 5. A pass earns the weight and a warning half. A score of 90 is an A, 75 a B, 60 a C and 40 a D. A page served over plain HTTP is an F.

Can I check a staging or internal site?

Only public sites. Private and reserved addresses, localhost, internal names and non-default ports are refused.

Why do my results differ from my browser's?

A CDN or server can send different headers by region, path or User-Agent. This shows exactly what came back to this one request.

Is what I enter stored?

No. Your IP address is used only to count requests for rate limiting, for one minute, and what you enter is not logged or kept.

Check a whole repository,
free.