Skip to main content

Security Headers Tester

v1.2.1

Validate common HTTP security headers and identify missing hardening controls.

Validates common HTTP security headers in a response header block — checks for HSTS, X-Frame-Options, CSP, X-Content-Type-Options, Referrer-Policy — and identifies missing hardening controls.

How to use
  • Paste HTTP response headers from browser DevTools, curl, or a proxy intercept.
  • Each expected security header is checked: present/absent, and value is evaluated.
  • Missing or weak headers are flagged with recommended values from OWASP guidelines.

Paste your HTTP response headers above and click Analyze to evaluate security posture.