Website diagnostics
Security Headers Checker
Check website security headers online with Web Health. Scan Content Security Policy, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy.
Understanding HTTP Security Headers
HTTP security headers serve as the first line of defense for web applications. By configuring appropriate security response headers, server administrators can mitigate common client-side attack vectors and achieve higher security ratings.
Essential Headers Inspected
- Strict-Transport-Security: Enforces HTTPS-only communication.
- Content-Security-Policy: Prevents unauthorized script execution and XSS.
- X-Frame-Options: Prevents clickjacking by disabling unauthorized framing.
- X-Content-Type-Options: Disables MIME-type sniffing (nosniff).
- Referrer-Policy: Controls privacy of cross-origin referrer URL data.
- Permissions-Policy: Restricts access to browser APIs (camera, mic, location).
Security Implementation Checklist
- Deploy HSTS with Preload: Include includeSubDomains and preload directives.
- Audit CSP Directives: Avoid 'unsafe-inline' and 'unsafe-eval' in production CSP.
- Set nosniff Flag: Always send 'X-Content-Type-Options: nosniff' header.
- Hide Server Tokens: Remove Server and X-Powered-By software version headers.
Frequently Asked Questions
HTTP security headers are directives sent by a web server in response to browser requests. They instruct modern web browsers to enable built-in security features, restricting vulnerabilities such as Cross-Site Scripting (XSS), clickjacking, MIME sniffing, and man-in-the-middle attacks.
