🧾 HTTP Headers Checker
Inspect any site’s response headers and get a security-header grade.
What HTTP headers are, and why they matter
Every time a browser loads a page, the server answers with the page itself plus a set of invisible instructions called response headers. They describe the content (type, length, caching rules) and, importantly, a handful of security headers that tell the browser how strictly to behave: always use HTTPS, refuse to be framed by other sites, never guess content types, and only load scripts from approved sources.
How the security grade works
- We check for the six headers that matter most: Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy.
- Each one present improves the grade. A Content-Security-Policy with a frame-ancestors rule also satisfies the framing check.
- Missing headers are listed with a plain-English reason to add them. Most are a single line of server or .htaccess configuration.
Frequently asked questions
Are missing security headers an emergency?
Not usually. They are hardening measures: your site works without them, but each one closes a known avenue of attack (clickjacking, script injection, protocol downgrade). Add them during routine maintenance; the grade improves immediately.
How do I add these headers on WordPress?
Either through your host's control panel, a security plugin, or a few lines in .htaccess / your server config. Add one at a time and re-check here, especially Content-Security-Policy, which can block legitimate scripts if written too strictly.
Why does the checker show a redirect or a different status than my browser?
The checker reports the final response after following redirects, the same as a browser. A 301 or 302 along the way is normal for http-to-https and www redirects; the grade uses the final page's headers.
What does the "Server" header reveal?
It often names the web server software and sometimes its version. That is free reconnaissance for attackers, which is why many hardened sites send a bare "Server" value or none at all.