Security Headers Test

Missing security headers leave your visitors open to attacks like clickjacking and code injection. Scan your site and get the exact headers to add.

FAQ

Which security headers should my site have?

At minimum HSTS, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options and Referrer-Policy. We check all of them.

Are missing headers dangerous?

They increase the risk of clickjacking, MIME sniffing and injection attacks. Adding them is quick and free.