Free tool · No sign-up · Server-assisted
Security Headers Scanner
Fetch a URL and grade the security headers it returns: Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy. Each one is explained in a sentence, with the header to add when it is missing, and the whole set rolls up to a letter grade.
Server-assisted · we fetch the URL from our server and send back only the headers it returns
Method & assumptions
- This is one of three server-assisted tools: your browser cannot read another origin's response headers, so our server fetches the URL and returns only its headers.
- The URL you enter is the only thing sent, and only to our server, which then requests it once. Nothing is stored.
- The grade weights the headers that matter most — CSP, HSTS, and framing protection carry more than the rest.
- We follow redirects to a public address only; private and internal targets are refused.
Other tools
More on the bench
- 01
Supabase Security Auditor
Point it at your project, find the holes. - 02
JWT Decoder
Paste a token, read what is inside. - 03
Secret & .env Scanner
Paste code or a .env, catch the leaked keys. - 04
CORS Tester
See exactly what a URL allows cross-origin. - 05
Base64 Encode / Decode
Text or files, both directions. - 06
URL Encode / Decode
Percent-encoding, both directions. - 07
JSON Formatter
Validate, pretty-print, or minify. - 08
UUID Generator
v4 and v7, one or a thousand.
Software engineering
We write the software
behind tools like these
Anyone hardening a site and wanting the same report a pen-tester would open with.
- Free diagnostics
- Same-day across most of the metro
- Named technicians
- No fix, no labour charge