Validate the URL
Only public HTTP and HTTPS URLs are allowed.
HTTP security scanner
Analyze your HTTP security headers instantly. Free, fast, and private.
How it works
HeaderCheckr scans a public URL, follows safe redirects, reads the response headers, then explains what is present, what is missing, and what to fix first.
Only public HTTP and HTTPS URLs are allowed.
The scanner fetches the site and follows safe redirects.
Missing headers include practical, copy-ready starting values.
Inside each report
It checks the main browser-facing security headers for a public website and shows which ones are present or missing.
The score reflects how many of the checked security headers are present on the final response. It is a useful baseline, not a full security audit.
HeaderCheckr grades scans from A+ down to F. A higher grade means more of the recommended browser security headers are present.
An A+ grade means the final response includes every security header HeaderCheckr currently checks for.
HeaderCheckr checks Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy.
No. The scanner is free to use and does not require signup.
No. Security headers are one layer. You still need secure code, patched dependencies, and safe server configuration.
Yes. HeaderCheckr sends an identifiable user agent string that includes HeaderCheckr when it fetches a site for analysis.