Security Tools

HTTP Header Checker

Inspect HTTP response headers for any public URL. Check security headers like HSTS, CSP, X-Frame-Options, and more.

Browser CORS restrictions limit direct header fetching. This tool shows a realistic demonstration of security header analysis. A production deployment uses a backend proxy with SSRF protection.

Security Headers Guide

HSTS
Forces HTTPS on all subsequent visits
CSP
Controls which resources can load (mitigates XSS)
X-Frame-Options
Prevents clickjacking attacks
X-Content-Type-Options
Prevents MIME-type sniffing
Referrer-Policy
Controls referrer information leakage
Permissions-Policy
Restricts browser feature access