What this tool checks
This tool sends a HEAD request to any URL and analyzes the response headers. It checks 10 critical security headers that protect against XSS, clickjacking, MIME sniffing, and other attacks. It also detects server software, CDN usage, and redirect chains.
More tools
Tech Stack Detector
Detect 467 technologies on any site.
Meta Tag Analyzer
Full meta tag audit for any URL.
Robots.txt Analyzer
Check AI & search crawler access.
FAQ
What is HSTS?+
HTTP Strict Transport Security tells browsers to only connect via HTTPS. Without it, users could be redirected to an insecure HTTP version of your site.
What is Content-Security-Policy?+
CSP controls which resources (scripts, styles, images) can be loaded on your page. It is the most important defense against XSS attacks.
What score should I aim for?+
A score of 80+ is good. 90+ is excellent. Focus on HSTS, CSP, and X-Content-Type-Options first — these provide the biggest security improvements.
Security headers on every page
Lumina checks HTTP status, security headers, and server info automatically — for free.
Add Lumina to Chrome — Free