Toolsone passive request · SSRF-protected

Security Header Checker

Check a site’s defensive response headers — Content-Security-Policy, HSTS, X-Frame-Options and X-Content-Type-Options — with a single passive probe.

http/https only. Private/loopback hosts are blocked (SSRF protection); one GET with no redirects.

What this checks

Caveats: the score is based on a single response-header probe; CDN/edge variations and JavaScript-executed behaviour are not captured.

Related Knowledge