Sign up free

Check Security Headers and Get an A+ to F Grade

Get an A+ to F grade for a site's security headers and the exact line to add for each gap.

About Security Headers Checker

A security headers check is a quick audit you can run on any site: your own before a security review, a client's after launch, or a vendor's before you trust it with data. Enter a URL and the grade is built from six headers: Strict-Transport-Security (HSTS), Content-Security-Policy, X-Frame-Options or CSP frame-ancestors, X-Content-Type-Options, Referrer-Policy and Permissions-Policy. A CSP that allows 'unsafe-inline' or 'unsafe-eval', or only reports, earns less.

The checker also shows the Cross-Origin-Opener, Resource and Embedder policies, and flags server version numbers and X-Powered-By headers that reveal your software, CORS that lets any site read responses with cookies, cookies missing Secure, HttpOnly or SameSite, and an http:// address that doesn't redirect to HTTPS. Each missing header comes with the exact line to add, such as Strict-Transport-Security: max-age=31536000; includeSubDomains. An A+ needs full marks on all six plus HSTS preload.

How to use Security Headers Checker

  1. 1
    Enter the URL

    Paste the page you want to grade, usually the home page.

  2. 2
    Click Check

    We load it from our server as a desktop browser and read the headers.

  3. 3
    Read the grade

    The grade sits at the top, and each check below says what's in place or missing.

  4. 4
    Add the missing lines

    Put the suggested headers in your server, CDN or panel settings, then check again.

Why use Cubfile for this

  • A+ to F grade

    Scored on HSTS, CSP, clickjacking protection, nosniff, Referrer-Policy and Permissions-Policy.

  • Exact fixes

    Every missing header comes with a ready line to add.

  • Leaks flagged

    Server versions, X-Powered-By and ASP.NET version headers are pointed out.

  • Cookies and CORS

    Cookie flags and a wildcard CORS policy that allows credentials are checked.

FAQ

Security Headers Checker: questions and answers

How is the security headers grade worked out?
HSTS and CSP are worth 25 points each, X-Frame-Options and X-Content-Type-Options 15 each, and Referrer-Policy and Permissions-Policy 10 each. 90 points or more is an A, and an A+ needs the full 100 plus HSTS with preload.
Will adding a Content-Security-Policy break my site?
It can, since a strict policy blocks scripts and styles from sources you didn't list. Start with Content-Security-Policy-Report-Only, read the reports, then switch to the enforced header. The checker flags a report-only policy separately.
Why is my Server header flagged?
A value like nginx/1.24.0 tells attackers which known bugs to try. Hide the version with server_tokens off in Nginx or ServerTokens Prod in Apache. To see what else gives your software away, such as the CMS or framework, try the Website Technology Detector.
Does the checker test the HTTP to HTTPS redirect?
Yes. For an https:// address it also opens the http:// version and checks that it redirects to HTTPS. The Redirect Checker follows that redirect hop by hop, with the status of each step.
Is the security headers checker free?
Yes, with no sign-up and no daily tasks used. It only reads what a normal visit returns and doesn't scan for vulnerabilities.
Share Security Headers Checker with a friendIt runs in any browser, and they can try it without signing up.

Related tools

WEB Website Speed TestTime DNS, connection, first byte and download for a page, and see what slows it down.
SSL SSL Certificate CheckerCheck a site’s certificate: issuer, expiry, domains covered and whether browsers trust it.
HTTP HTTP Status Code CheckerCheck the status code of one URL or a whole list at once.
HTTP Redirect CheckerFollow every redirect hop, with status codes and timing, and catch loops.
WEB Website Technology DetectorSee the CMS, frameworks, analytics, CDN and server a website uses.
WEB Is It Down?Find out whether a site is down for everyone, and which step fails.
WEB CDN CheckerFind out whether a domain is behind a CDN, and which one.
WEB GZIP and Brotli CheckerCheck whether a page is sent compressed and how much it saves.