Security Headers Checker
Check whether a public URL sends common browser security headers such as CSP, HSTS, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy.
Free Tools
Use focused, lightweight checks for individual website security signals. For CMS detection, vulnerability applicability, exposure review, DNS/email posture, third-party inventory, and report exports, run the full CMS audit.
Check whether a public URL sends common browser security headers such as CSP, HSTS, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy.
Review HTTPS reachability, certificate validity, hostname match, expiry window, TLS versions, and HTTP-to-HTTPS redirect behavior.
Check robots.txt, sitemap references, reachable sitemap URLs, and sensitive-looking paths advertised to crawlers.
Review homepage Set-Cookie headers for Secure, HttpOnly, SameSite, and basic cookie hygiene indicators.
Check whether an HTTPS homepage references insecure HTTP scripts, styles, media, iframes, or form actions.
Review apex, www, HTTP, and HTTPS variants for redirect behavior and canonical destination consistency.
Identify public CMS, CDN, server, analytics, and JavaScript library hints from the homepage response.
Review SPF, DMARC, MX, and related email security signals for a domain.
Identify public CMS signals and confidence indicators without generating a full report.