Security Headers Checker
Audit your HTTP security headers — CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy and more. Get a grade and fix recommendations.
What it checks: every major security header (CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy) against current best practices, with a letter grade and copy-pasteable fix snippets for Nginx and Apache.