Security Headers Checker
Inspect HTTP security headers on any public URL.
- slug
- security-headers-checker
- visibility
- Public
- risk
- safe
- level
- 0
What this tool does.
Fetches a URL server-side and reports on the presence, absence and value of the most common security response headers.
Useful to quickly audit the security posture of a public endpoint without running a full scanner.
Run this tool.
Submit an input and see the runner output here. Execution is server-side and governed by the policy shown in the sidebar.
Everything runs server-side. Inputs and outputs are subject to the tool's policy shown in the sidebar.
Dev-docs · 2 documents.
Related articles.
What Security Headers Actually Tell You
A practical guide to interpreting HTTP security headers as evidence: what each control changes in the browser, what absence means, and why header counts are not security grades.
Getting Started with Public Surface Analysis
A practical, passive-first workflow for reading DNS, HTTP, robots, metadata, technology and historical signals without overclaiming.
A Responsible Method for Reconnaissance on Public Web Surfaces
A practical framework for deciding what to collect, when public research becomes active testing, how to define authorization and scope, and when to stop.
How to Turn Weak Signals into Better Questions
A practical OSINT reasoning framework for turning ambiguous observations into testable hypotheses, seeking disconfirming evidence and expressing conclusions with calibrated confidence.