/security-headers
Security Headers
Check for HSTS, CSP, X-Frame-Options and other security headers.
About Security Headers
Security Headers checks a website's response for the specific headers browsers rely on to enforce protections like forced HTTPS, restricted script sources and clickjacking prevention, reporting which are present and which are missing.
Each header is scored individually with an explanation of what it actually protects against, rather than folded into a single pass or fail result, since a site can be missing one header while every other protection is correctly configured.
Run this after a server configuration change, as part of a routine security review, or whenever you want a plain answer to what specific protections a site's headers are and are not currently providing.
