HTTP Security Headers Audit
100% client-side. Your data never leaves this page. Verify: DevTools → Network.
Best-effort. Browsers only expose cross-origin headers the server allows via CORS. Paste mode gives a complete audit.
This grades the security-relevant HTTP response headers a site sends. The audit runs entirely in your browser. In paste mode nothing is sent anywhere.
How to copy a site's headers:
- Open DevTools (F12) → Network tab, reload the page.
- Click the top (document) request → Headers → Response Headers.
- Copy them and paste above. Or run
curl -I https://example.comand paste that.