Security Headers Check

Audit HTTP response headers for OWASP security best practices and get a security score.

freeworks offlinenothing uploaded
Input
Output

About security headers check

Security Headers Check needs nothing from a server once the page has loaded. Leave it open on a train with no signal and it carries on.

The parsing, the maths and the formatting all happen in JavaScript on this page. No request carries your input anywhere, because there is no endpoint for one to reach.

You will find it under Web security, alongside 7 other tools for the same sort of job.

Checks CSP, HSTS, X-Frame-Options, Referrer-Policy, and 7 more headers.

How to use it

01
Start it
Every control is on the tool itself. Keyboard shortcuts, where there are any, are listed beside it.
02
Watch it run
It updates in the page as you go. Nothing is sent anywhere, so it keeps working with the network off.
03
Close when done
Nothing is stored between visits. Reloading gives you a clean start rather than picking up where you left off.

Examples

Audit four common security headers
Analyze HTTP headers including HSTS, CSP, X-Content-Type-Options, and X-Frame-Options
Input
Strict-Transport-Security: max-age=31536000
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
Content-Security-Policy: default-src 'self'
Output
Security Headers Analysis
Score: 55/100 (Grade: D)
Present: 4/11

Details:
  [+] content-security-policy: default-src 'self'
      PRESENT - Prevents XSS and data injection attacks
  [+] strict-transport-security: max-age=31536000
      PRESENT - Forces HTTPS connections
  [+] x-content-type-options: nosniff
      PRESENT - Prevents MIME type sniffing
  [+] x-frame-options: DENY
      PRESENT - Prevents clickjacking
  [-] x-xss-protection
      MISSING (optional) - Legacy XSS filter (deprecated)
  [-] referrer-policy
      MISSING (recommended) - Controls referrer information
  [-] permissions-policy
      MISSING (recommended) - Controls browser features
  [-] cross-origin-opener-policy…

Questions

Does Security Headers Check work offline?+

Yes. It is JavaScript running in this tab, so once the page has loaded it needs nothing further from the network. Put the machine in flight mode and it carries on. Nothing you do here is sent anywhere, because there is nowhere for it to go.

Does it remember anything between visits?+

No. Reload the page and it starts from nothing. There is no account, no saved state and no cookie holding your last session. That is a deliberate trade: it cannot lose your data because it never keeps any.

Is it accurate?+

Timing comes from performance.now(), the high resolution clock the browser provides, rather than from setInterval, which drifts by a few milliseconds every tick and compounds over minutes. What can still shift things is the browser throttling a tab in the background, so leave it visible if the timing matters.

Does it make a sound?+

Where a sound makes sense, it is generated with the Web Audio API rather than loaded as a file, so there is nothing to download and nothing to block. Browsers refuse to start audio until you have interacted with the page, which is why the first press is what switches it on.

Can I use Security Headers Check on a phone?+

Yes. The controls are sized for touch and the layout collapses to one column on a narrow screen. Bear in mind that a phone locking its screen will suspend the page, and timing stops with it.