Free Security Headers Check
A passive inspection of what your server publicly returns: HTTPS enforcement, certificate health, HSTS, CSP, frame protection, cookie flags and mixed content.
Your results
Unlock the full report
Every check, weight, recommendation, and PDF, verify once, stay unlocked.
This free check inspects the security headers and TLS certificate your server returns publicly. It covers HTTPS enforcement, certificate validity and expiry, HSTS, Content-Security-Policy, X-Frame-Options, Referrer-Policy, cookie flags and mixed content. It is a passive inspection, not a penetration test or vulnerability scan.
What this tool checks
HTTPS & TLS
Enforcement, certificate validity, expiry, protocol version
HSTS
Presence, max-age, subdomain coverage
Content-Security-Policy
Presence and unsafe-inline usage
Frame protection
X-Frame-Options or CSP frame-ancestors
Cookies
Secure, HttpOnly, SameSite flags
Mixed content
Insecure resources on secure pages
How scoring works
Every weight is published. Category totals sum to 100.
Free preview vs unlocked report
Run first. Verify only when the sample issue proves the scan is useful.
Why it matters
State the boundary plainly: this tool looks at what your server hands to any visiting browser. It does not probe, scan ports, enumerate paths, test for injection, or attempt anything a normal page load wouldn’t do. That’s a deliberate limit, partly technical and partly legal: running active security scans against a domain you don’t own is a genuine problem, and we’re not going to do it because someone typed a URL into a form. What passive inspection does catch is worth catching. Missing HSTS, absent CSP, cookies without HttpOnly, and certificates quietly approaching expiry are common, consequential, and usually fixed at the server or CDN level in minutes. If you need real security testing, you need a penetration test from a security firm. That’s a different service, and we’ll say so rather than pretend this substitutes for it.
Methodology
Paste any public URL
We fetch the page the way a browser and crawler would, no login walls, no probing.
Collect signals once
HTML, headers, robots/sitemap, and optional Lighthouse lab data feed every tool from one pass.
Score with published weights
Each check has a fixed weight that sums to 100. N/A checks leave the denominator so empty pages aren’t unfairly punished.
Preview free, unlock the rest
See your score and the top issue immediately. Verify email for the full checklist, fixes, and PDF.
Want this fixed rather than measured?
The scan tells you what is wrong. A free 48-hour audit tells you what it costs to fix, in what order, and how long it takes.
Get a free 48-hour audit and a written scope
Send your URL and the one number this project has to move. A technical lead replies within one business day, and qualified projects receive a written fixed-price scope with milestones and a delivery date within two. Client references are available under NDA during scoping.
Talk to the team building itNeed Website Development?
We’ll turn this report into a scoped build plan, not a slide deck.
Free Security Headers Check FAQs
Is this a vulnerability scan?
No. It’s a passive inspection of publicly returned headers and certificates. No probing of any kind.
Why not scan more deeply?
Active scanning of a domain without the owner’s authorization is legally fraught. We won’t do it on a URL a stranger submitted.
What’s HSTS?
A header telling browsers to only ever connect over HTTPS, preventing downgrade attacks.
What’s a CSP?
Content-Security-Policy: controls which resources a page may load, the main defense against cross-site scripting.
My certificate expires soon, how urgent?
Under 7 days is flagged critical. An expired certificate makes your site unreachable for most visitors with a full-page browser warning.
Do I need a real penetration test?
If you handle payments, personal data or logins, yes. This is a hygiene check, not a substitute.
Get a timeline, a price range and a next step.
Send your URL and the metric this project has to move. A free 48-hour audit comes back with a prioritized fix list, and qualified projects get a written fixed-price scope within two business days.