Skip to content

Free tools

Check your website’s security headers

Type your address. Each header on your homepage gets a letter grade and one sentence on what it protects your visitors from.

The check loads your homepage once, the way a browser would, and reads only the response headers. The page content is not read or stored.

What the check looks at

Strict-Transport-Security (HSTS)
Makes browsers use the encrypted version of your site, every time.
Content-Security-Policy (CSP)
Decides which scripts may run on your pages. The strongest defence against injected code.
X-Frame-Options and frame-ancestors
Stops other sites from showing your page inside a frame to trick people into clicking.
X-Content-Type-Options
Stops the browser from guessing file types, which could turn an uploaded file into a script.
Referrer-Policy
Limits how much of your page address is passed on to other sites.
Permissions-Policy
Switches off the camera, microphone and location on pages that do not use them.
Cookies
Whether cookies set by your homepage are marked Secure, HttpOnly and SameSite.

Questions

What are security headers?

Short instructions your server sends with every page, which the visitor never sees. They tell the browser how to protect people on your site: always use https, do not run scripts from unknown places, do not let other sites frame the page. They cost nothing and are set once.

How do I add security headers in WordPress?

Usually in the server configuration: the .htaccess file on Apache hosting, the site configuration on nginx, or rules in Cloudflare if you use it. There are plugins that add them too. The text that appears under your result lists the exact lines to add, so you can pass it on as it is.

Does a low grade mean my site has been hacked?

No. Headers are an extra layer that limits the damage when something else goes wrong. A site graded F can be perfectly clean, and a site graded A can still run an outdated plugin. The full scan looks at both.

Can Content-Security-Policy break my site?

Yes, if it is switched on in one go. A strict policy blocks scripts it does not know about, including ones your site needs, like analytics or a chat widget. That is why it is first rolled out in report-only mode, which logs what would be blocked without blocking it.

How is the grade calculated?

Each header gets a letter from A to F. The overall grade is their average, with HSTS and Content-Security-Policy counting double because they protect the most. Cookies count only when the homepage sets any. The grade covers the homepage; other pages can send different headers.

Other free tools

Read more

The full scan runs 20+ checks in about 90 seconds.

Free, no account. You get a plain-language report and a brief for your developer.

Go to the full scan