All Tools View Categories About Contact Privacy

Security Headers Checker

Score pasted response headers against security best practices.

Runs entirely in your browser - nothing is uploaded and no cloud connection is made.
Your scored report will appear here.
-
score
-
grade

About Security Headers Checker

HTTP security headers are one of the cheapest, highest-impact hardening steps available, yet production responses routinely ship without them. Manually reading response headers to confirm HSTS, CSP and the rest is tedious and easy to get wrong. The Security Headers Checker scores pasted response headers against a fixed best-practice checklist, reports a 0-100 score and grade, and names exactly which protections are missing - all without making any live connection to a server.

At the heart of the configuration are a handful of directives. Strict-Transport-Security forces browsers to use HTTPS and is the backbone of downgrade protection. Content-Security-Policy limits where scripts and assets may load from, cutting cross-site scripting risk. X-Content-Type-Options set to nosniff it stops browsers from MIME-sniffing responses away from the declared type. X-Frame-Options DENY or SAMEORIGIN prevents your pages being framed for clickjacking. Referrer-Policy controls how much referrer URL is sent to other origins, limiting data leakage. Permissions-Policy restricts powerful browser features such as geolocation and camera per origin. Together they shape how the server behaves, and the tool assembles them in the right context so the result is valid on the first try.

Common mistakes are easy to make. Pasting response body instead of headers means every check fails because no header lines are found. Forgetting HSTS leaves the site open to SSL-stripping downgrade attacks on first visit. Shipping a weak or absent CSP gives XSS far more room to execute. Assuming a 200 response is "secure" ignores that security lives in the headers, not the status. The generator anticipates each of these and either sets a safe default or rejects the input with a clear message before anything is written to your clipboard.

Validation is strict because small configuration errors fail in subtle ways. Every input is checked for plausibility, and after the block is assembled it is re-parsed by a built-in tokenizer so unbalanced braces, missing semicolons or stray characters cannot reach your clipboard. Stat cards report line and block counts, and copy, download and print exports are one click away. Everything runs in your browser; nothing you type is transmitted to any server.

In practice this block drops into any standard nginx install. Save the output as a file under /etc/nginx/conf.d/ (or sites-available with a symlink), run nginx -t to confirm the syntax, then reload with nginx -s reload. Because the generator emits a single, self-contained server block with no hidden dependencies, it composes cleanly with your existing caching, logging and security configuration without directive collisions.

Beyond producing correct config, the tool is a reference you can read back and learn from. Each control maps to a real nginx directive, the sample button shows a complete working block in seconds, and clearing the form resets every field to its safe default. Standardising on a generator like this removes per-developer variation, keeps your configuration readable, and gives you a repeatable, auditable setup that passes nginx -t on the first try.

When something looks wrong in production, the first move is always to re-run nginx -t and inspect /var/log/nginx/error.log; most failures surface there with a line number. The access log records every request, so a sudden spike or a wall of 499 responses points straight at backend or timeout problems the generator helps you avoid in the first place.

This server block is designed to sit alongside - not fight - your other configuration. Because it declares its own server_name and a single, self-contained set of directives, you can drop it into conf.d without worrying about collisions with global caching, logging or security snippets that live elsewhere in the nginx tree.

For a production site, pair this block with TLS termination: serve on 80 for the redirect or health checks, and place the encrypted listener (or a front-end load balancer / CDN) in front so clients always speak HTTPS. The generator keeps that boundary clean so the two layers compose instead of overlapping.

If a change ever needs to be undone, the output is plain text you control: delete the file from conf.d, re-run nginx -t, and reload. There is no database and no hidden state, so rolling back is as simple as restoring the previous version from version control or your own backup.

Performance and correctness both benefit from explicit configuration. Defaults baked into the generator reflect current best practice rather than decades-old forum snippets, so the block you ship today will not surprise you with deprecated directives or insecure fallbacks six months from now.

For teams, a generated block is also documentation. New engineers can read the exact directives in place, compare them against the sample, and learn the relevant nginx behaviour without reverse-engineering a hand-maintained file that drifted from its original intent.

Features

  • Strict-Transport-Security - forces browsers to use HTTPS and is the backbone of downgrade protection.
  • Content-Security-Policy - limits where scripts and assets may load from, cutting cross-site scripting risk.
  • X-Content-Type-Options - set to nosniff it stops browsers from MIME-sniffing responses away from the declared type.
  • X-Frame-Options - DENY or SAMEORIGIN prevents your pages being framed for clickjacking.
  • Referrer-Policy - controls how much referrer URL is sent to other origins, limiting data leakage.
  • Permissions-Policy - restricts powerful browser features such as geolocation and camera per origin.
  • Self-verifying output re-parsed before display.
  • Copy, Download and Print exports.
  • Load-sample button fills realistic values.
  • Statistics cards for quick checks.
  • Runs entirely in your browser - nothing uploaded.

How to Use

  1. Capture the response headers from your server or proxy.
  2. Paste them into the text area, one "Name: value" per line.
  3. Click Score headers (or Load sample) to run the checklist.
  4. Read the per-header PASS/FAIL lines.
  5. Note the overall Score and Grade.
  6. Add the missing headers to your server or CDN configuration.
  7. Re-paste and re-score until you reach grade A.

Examples

Example 1 - Perfect set all six headers present scores 100 and reports grade A.

Example 2 - Only server header a bare response scores low with every check failing.

Example 3 - HSTS only a single good header shows one PASS and five FAIL lines.

Example 4 - Missing CSP headers without CSP still pass five checks but lose points.

Example 5 - nosniff spelled wrong a mistyped X-Content-Type-Options value fails the nosniff check.

Benefits

  • Fixed best-practice checklist, no guessing.
  • Clear 0-100 score and letter grade.
  • Names exactly which headers are missing.
  • No live fetch - safe to use on sensitive data.
  • JSON export for tracking over time.
  • Private: everything runs in your browser.

Frequently Asked Questions

Does this fetch a live URL?
No. It only scores the headers you paste; the tool makes no network requests at all.
Which headers are scored?
HSTS, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy and Permissions-Policy.
What is a good score?
Grade A (90+) means all six headers are present; lower grades show which protections are missing.
Why is CSP important?
CSP limits where scripts and other resources can load from, dramatically reducing cross-site scripting risk.
Is X-Frame-Options still needed?
It remains a widely supported clickjacking defense even where CSP frame-ancestors is also set.
What does HSTS do?
HSTS tells browsers to enforce HTTPS, preventing plaintext downgrade and cookie hijacking attacks.
Can I export the report?
Yes - copy, download or print the scored report, and download a JSON summary via the JSON button.
Is anything uploaded?
No. The headers you paste never leave your browser.