Free tool

Security headers checker, in plain English.

Put in a web address and we will load the page once and tell you which of the six headers that protect its visitors are in place, what each one does, and how to fix the ones that are missing. Free, no sign up, and nothing is kept.

Check a site

Which headers does your website send?

We fetch the page once, read the headers that come back, and keep nothing. Public websites only.

What it checks

Six headers, each closing off a different trick

Security headers are instructions a website sends with every page, telling the browser what that page is allowed to do. Most take one line to add, and none of them cost anything.

Strict-Transport-Security

Tells browsers to use HTTPS for the site every time, so a visitor on hostile wifi cannot be dropped onto an unencrypted copy.

Content-Security-Policy

Lists where scripts, styles and images may load from. The strongest defence against an injected script, and the hardest to get right.

X-Frame-Options

Stops another site loading yours inside a frame and tricking people into clicking things they cannot see.

X-Content-Type-Options

Stops browsers second guessing a file’s type and running something that was uploaded as a picture.

Referrer-Policy

Limits how much of the page address is passed on when somebody clicks a link to another site.

Permissions-Policy

Switches off browser features the site never uses, such as the camera, the microphone and location.

Questions

The things people ask first

Does a good score mean the website is secure?

No. Headers protect the people visiting the site. They say nothing about the server behind it, the admin passwords, the plugins or the backups. What they do show, quickly and publicly, is whether anybody has looked, which is why they are worth checking.

Is it all right to check a website that is not mine?

Yes. The checker loads the page once, the same way a browser does, and reads the headers that come back. It does not scan, probe or try anything. If you are checking a supplier, it is a fair question to raise with them.

Do you keep the addresses people check?

No. The address is used to fetch the page and build the result, and then it is dropped. Nothing is written to a database and there is no cookie. The privacy notice says the same.

How do I add the headers that are missing?

Wherever the site is hosted. Web servers such as Apache, Nginx and IIS set them in their configuration, most content delivery networks, Cloudflare included, can add them without touching the site, and many hosting panels have a setting for it. If you do not know where your site is hosted, that is the first thing to find out, and we are happy to help you work it out. Whether headers matter for a small business site covers which to fix first.

Why does the result say the site answered with an error?

Some sites put a firewall or bot filter in front of their pages that turns away automated requests, ours included. When that happens you see the headers on the error response, which can differ from the real pages. Loading the site in your own browser and opening the developer tools shows the real ones.

Next step

Want somebody to look at the rest?

Headers are the part anybody can see from outside. Tell us what your website runs on and who looks after it, and we will tell you what is worth checking behind it.

IT support and cyber security across Wales and beyond

Based in Cardiff, working across Wales and the West.