Check your website’s security headers
Type your address. Each header on your homepage gets a letter grade and one sentence on what it protects your visitors from.
What the check looks at
- Strict-Transport-Security (HSTS)
- Makes browsers use the encrypted version of your site, every time.
- Content-Security-Policy (CSP)
- Decides which scripts may run on your pages. The strongest defence against injected code.
- X-Frame-Options and frame-ancestors
- Stops other sites from showing your page inside a frame to trick people into clicking.
- X-Content-Type-Options
- Stops the browser from guessing file types, which could turn an uploaded file into a script.
- Referrer-Policy
- Limits how much of your page address is passed on to other sites.
- Permissions-Policy
- Switches off the camera, microphone and location on pages that do not use them.
- Cookies
- Whether cookies set by your homepage are marked Secure, HttpOnly and SameSite.
Questions
What are security headers?
Short instructions your server sends with every page, which the visitor never sees. They tell the browser how to protect people on your site: always use https, do not run scripts from unknown places, do not let other sites frame the page. They cost nothing and are set once.
How do I add security headers in WordPress?
Usually in the server configuration: the .htaccess file on Apache hosting, the site configuration on nginx, or rules in Cloudflare if you use it. There are plugins that add them too. The text that appears under your result lists the exact lines to add, so you can pass it on as it is.
Does a low grade mean my site has been hacked?
No. Headers are an extra layer that limits the damage when something else goes wrong. A site graded F can be perfectly clean, and a site graded A can still run an outdated plugin. The full scan looks at both.
Can Content-Security-Policy break my site?
Yes, if it is switched on in one go. A strict policy blocks scripts it does not know about, including ones your site needs, like analytics or a chat widget. That is why it is first rolled out in report-only mode, which logs what would be blocked without blocking it.
How is the grade calculated?
Each header gets a letter from A to F. The overall grade is their average, with HSTS and Content-Security-Policy counting double because they protect the most. Cookies count only when the homepage sets any. The grade covers the homepage; other pages can send different headers.
Other free tools
- SSL certificate checkerWhen does the certificate expire, who issued it, and do browsers trust it?
- SPF, DKIM and DMARC checkCan someone send email that looks like it came from your business?
- Cookies before consent checkDoes your site set cookies or load Google Analytics and Meta Pixel before anyone clicks accept?
The full scan runs 20+ checks in about 90 seconds.
Free, no account. You get a plain-language report and a brief for your developer.
Go to the full scan