Site Safety Checker
Inspect HTTPS, TLS, DNS, redirects and security headers in one deterministic safety score.
Check CSP, HSTS, X-Content-Type-Options, Permissions-Policy and other HTTP security headers with a clear score.
Your input is processed only as required by this tool.
Security headers tell browsers how to handle risky capabilities and cross-origin behavior. This checker reads the response headers from the final public URL and scores the presence of protections such as Content Security Policy, HSTS, framing controls and referrer policy.
A missing header is not automatically a vulnerability, but it may remove an important defense layer. Review each finding in the context of the application instead of chasing a perfect score blindly.
Headers can differ by route, authentication state, CDN edge and response type. Checking the home page is a useful baseline, not a complete application security assessment.
There is no single universal answer, but a well-designed Content-Security-Policy and correct HTTPS/HSTS configuration provide important layers for many web applications.
You should not. Some policies can break legitimate functionality when copied without understanding the application. Configure them deliberately and test the result.