OneFirewall Alliance

HTTP Security Headers Checker

Audit a website's HTTP security headers — detect missing or misconfigured protections

Enter a URL and the checker inspects the response headers that harden a site against common web attacks, including HSTS, Content-Security-Policy, X-Frame-Options and Referrer-Policy. Missing or weak headers are highlighted with guidance on what to set. More free security tools.

Headers are fetched via multiple CORS proxies (tried in sequence). corsproxy.io passes through actual server response headers — results closest to what real browsers see.

Need a full web application security review and hardening assessment?

If you like this tool, Speak with OneFirewall