About Security Headers Checker
A security headers check is a quick audit you can run on any site: your own before a security review, a client's after launch, or a vendor's before you trust it with data. Enter a URL and the grade is built from six headers: Strict-Transport-Security (HSTS), Content-Security-Policy, X-Frame-Options or CSP frame-ancestors, X-Content-Type-Options, Referrer-Policy and Permissions-Policy. A CSP that allows 'unsafe-inline' or 'unsafe-eval', or only reports, earns less.
The checker also shows the Cross-Origin-Opener, Resource and Embedder policies, and flags server version numbers and X-Powered-By headers that reveal your software, CORS that lets any site read responses with cookies, cookies missing Secure, HttpOnly or SameSite, and an http:// address that doesn't redirect to HTTPS. Each missing header comes with the exact line to add, such as Strict-Transport-Security: max-age=31536000; includeSubDomains. An A+ needs full marks on all six plus HSTS preload.
How to use Security Headers Checker
- 1Enter the URL
Paste the page you want to grade, usually the home page.
- 2Click Check
We load it from our server as a desktop browser and read the headers.
- 3Read the grade
The grade sits at the top, and each check below says what's in place or missing.
- 4Add the missing lines
Put the suggested headers in your server, CDN or panel settings, then check again.
Why use Cubfile for this
- A+ to F grade
Scored on HSTS, CSP, clickjacking protection, nosniff, Referrer-Policy and Permissions-Policy.
- Exact fixes
Every missing header comes with a ready line to add.
- Leaks flagged
Server versions, X-Powered-By and ASP.NET version headers are pointed out.
- Cookies and CORS
Cookie flags and a wildcard CORS policy that allows credentials are checked.