📞 (866) 965-8749✉️ sales@handsontech.io📍 2108 N ST STE N, Sacramento, CA 95816
Serving the U.S., ET · CT · MT · PTin𝕏ig
Free tool

Free Security Headers Check

A passive inspection of what your server publicly returns, HTTPS enforcement, certificate health, HSTS, CSP, frame protection, cookie flags and mixed content.

No signupto run a scan
~30stypical result time
Freepreview on every tool
The short answer

This free check inspects the security headers and TLS certificate your server returns publicly. It covers HTTPS enforcement, certificate validity and expiry, HSTS, Content-Security-Policy, X-Frame-Options, Referrer-Policy, cookie flags and mixed content. It is a passive inspection, not a penetration test or vulnerability scan.

What you get

What this tool checks

HTTPS & TLS

Enforcement, certificate validity, expiry, protocol version

HSTS

Presence, max-age, subdomain coverage

Content-Security-Policy

Presence and unsafe-inline usage

Frame protection

X-Frame-Options or CSP frame-ancestors

Cookies

Secure, HttpOnly, SameSite flags

Mixed content

Insecure resources on secure pages

Weights

How scoring works

Every weight is published. Category totals sum to 100.

CategoryWeightChecks
HTTPS & TLS385
HSTS112
Content-Security-Policy101
Frame protection214
Mixed content81
Cookies123
Compare

Free preview vs unlocked report

Run first. Verify only when the sample issue proves the scan is useful.

Free previewUnlocked
Overall score + bandYesYes
Category breakdownYesYes
Issue counts by severityYesYes
Top failing issue (full detail)YesYes, every issue
Full check list + weightsHiddenYes
All recommendations + PDFHiddenYes
Context

Why it matters

State the boundary plainly: this tool looks at what your server hands to any visiting browser. It does not probe, scan ports, enumerate paths, test for injection, or attempt anything a normal page load wouldn't do. That's a deliberate limit, partly technical and partly legal: running active security scans against a domain you don't own is a genuine problem, and we're not going to do it because someone typed a URL into a form. What passive inspection does catch is worth catching. Missing HSTS, absent CSP, cookies without HttpOnly, and certificates quietly approaching expiry are common, consequential, and usually fixed at the server or CDN level in minutes. If you need real security testing, you need a penetration test from a security firm, that's a different service and we'll say so rather than pretend this substitutes for it.

Methodology

Methodology

01

Paste any public URL

We fetch the page the way a browser and crawler would, no login walls, no probing.

02

Collect signals once

HTML, headers, robots/sitemap, and optional Lighthouse lab data feed every tool from one pass.

03

Score with published weights

Each check has a fixed weight that sums to 100. N/A checks leave the denominator so empty pages aren’t unfairly punished.

04

Preview free, unlock the rest

See your score and the top issue immediately. Verify email for the full checklist, fixes, and PDF.

Need Website Development?

We’ll turn this report into a scoped build plan, not a slide deck.

Explore Website DevelopmentTalk to us
FAQs

Free Security Headers Check FAQs

Is this a vulnerability scan?

No. It's a passive inspection of publicly returned headers and certificates. No probing of any kind.

Why not scan more deeply?

Active scanning of a domain without the owner's authorisation is legally fraught. We won't do it on a URL a stranger submitted.

What's HSTS?

A header telling browsers to only ever connect over HTTPS, preventing downgrade attacks.

What's a CSP?

Content-Security-Policy: controls which resources a page may load, the main defence against cross-site scripting.

My certificate expires soon, how urgent?

Under 7 days is flagged critical. An expired certificate makes your site unreachable for most visitors with a full-page browser warning.

Do I need a real penetration test?

If you handle payments, personal data or logins, yes. This is a hygiene check, not a substitute.

Built for founders who are done waiting on agencies.

One team. One contract. Working software every two weeks.

Get your free auditEmail us directly