Free Security Tool
Scan your website's HTTP security headers. Check for Content-Security-Policy, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy.
This tool inspects the HTTP response headers your server sends and evaluates them against security best practices. It checks for Content-Security-Policy (CSP), Strict-Transport-Security (HSTS), X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, Cross-Origin-Opener-Policy (COOP), and Cross-Origin-Embedder-Policy (COEP). It also checks for server information disclosure and secure cookie flags.
Security headers are your server's first line of defense against common web attacks. Without a Content-Security-Policy, your site is vulnerable to cross-site scripting (XSS). Without X-Frame-Options, attackers can embed your site in an iframe for clickjacking. Missing HSTS allows protocol downgrade attacks. These headers cost nothing to implement but significantly reduce your attack surface.
Security is just one of 11 categories PageGrader audits. Run a full scan to see your scores across SEO, performance, accessibility, security, content quality, mobile, links, images, social sharing, AI readiness, and best practices.
Run a full website audit200+ checks across 11 categories. Free, no signup required.