Free security headers checker

Check the browser security headers your website sends.

Scan a live public response for six common security headers: HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy.

Free · No signup required · Live public website check

What this tool checks

Six browser-facing security headers

Strict-Transport-Security

Checks whether HSTS is present on the response.

Content-Security-Policy

Checks whether a CSP header is present.

X-Frame-Options

Checks for legacy framing protection.

X-Content-Type-Options

Checks for the nosniff response header.

Referrer-Policy

Checks whether a referrer policy header is present.

Permissions-Policy

Checks whether a permissions policy header is present.

Interpret the result

Presence is a useful baseline, but it is not a full security audit.

Security headers tell browsers to apply additional protections around transport, framing, content execution, referrer data and browser features. Missing headers are worth reviewing, but a header can also be present with a weak or application-specific policy.

SiteState currently reports presence for a curated six-header baseline. It does not grade policy strength or claim that a website is secure based only on these headers.

Methodology

SiteState reads the main document response headers from the live browser check and reports whether six curated security headers are present. The current tool does not grade individual policy values.

FAQ

Common questions about this website check

Which security headers does SiteState check?

Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy.

Does a passing header check mean my website is secure?

No. Security headers are only one layer of website security. SiteState currently checks presence, not the full strength or correctness of every policy.

Does SiteState show raw response header values?

The current free report focuses on presence and missing-header names rather than exposing a complete raw-header inventory.

Can I run this check without signup?

Yes. The one-off security headers check is available without creating an account.

Continuous website state

Need ongoing history? Website monitoring turns one-off health checks into continuous state, incidents and change detection. Website monitoring.

A one-off check tells you what is happening now.

SiteState continuous monitoring keeps watching and builds history for changes, incidents and regressions.