What this checker does

It requests the URL with a plain GET, follows up to five redirects one hop at a time, and shows the status and headers of every step. The final response's headers are checked against the security headers every site should send, and its caching headers are translated into plain English.

How to read the checklist

  • ✓ the header is present and configured sensibly. ! present but weak, or missing where browsers have a safe default. ✗ missing or unsafe.
  • Strict-Transport-Security only counts on HTTPS. Six months (max-age=15552000) is the minimum for preload lists; a year is common.
  • Content-Security-Policy is the hardest to get right. A policy with 'unsafe-inline' scripts and no nonces or hashes does little against XSS.
  • Framing passes with CSP frame-ancestors or X-Frame-Options: DENY/SAMEORIGIN.
  • Cookies: session cookies should have Secure, HttpOnly and a SameSite value.
  • The score is a quick summary, not an audit; a static brochure site and a banking app need different policies.

Common mistakes

  • Setting headers only on some responses. nginx's add_header is dropped in a location that has its own add_header, and error pages often lose them. Use always and check a 404 page too.
  • HSTS on HTTP. Browsers ignore Strict-Transport-Security over plain HTTP; send it on the HTTPS response.
  • Copying a CSP that allows everything. default-src * 'unsafe-inline' 'unsafe-eval' is the same as no policy. Start with Content-Security-Policy-Report-Only and tighten.
  • Caching private pages. Pages for logged-in users need Cache-Control: private or no-store, or a CDN may serve one user's page to another.
  • Redirect chains. http to https to www to a trailing slash is three round trips. Redirect once, straight to the final URL.

FAQ

Which security headers matter most?

Strict-Transport-Security (forces HTTPS), Content-Security-Policy (limits script sources, the main defence against XSS), X-Content-Type-Options: nosniff, and frame-ancestors or X-Frame-Options against clickjacking. Referrer-Policy and Permissions-Policy are good hygiene.

Is X-XSS-Protection still needed?

No. Modern browsers removed the XSS auditor it controlled, and the header can even introduce bugs. Use a Content-Security-Policy instead; this checker does not score X-XSS-Protection.

Why does the checker use GET and not HEAD?

Many servers and CDNs answer HEAD differently or not at all. A GET returns the real headers; the body is not downloaded.

Can it check pages behind a login or on my local network?

No. It sends no cookies and only fetches public addresses on ports 80 and 443; private, local and cloud-metadata addresses are refused. To check an internal site, use curl -I from inside the network.

Why do I see different headers than in my browser?

Servers can vary headers by user-agent, cookies, location or HTTP version, and CDNs may serve a cached copy. This checker identifies itself as simpleprog-tools and fetches from one location.