HTTP security headers analyzer
Paste HTTP response headers and review HSTS, CSP, Report-Only policies, Reporting-Endpoints/Report-To/NEL, Document-Policy, Origin-Agent-Cluster, cross-origin isolation headers, and Set-Cookie attributes locally in your browser.
Local paste analyzer; no URL request, no input submission, no ranking label, no full security audit. Input limit is 64 KiB.
The profile only changes recommendation weight and ordering; it does not request URLs, read or write URL parameters, or persist input.
-Top priority
0High priority
0Needs review
0Info
Header groups
Grouped only by header names and rules covered on this page. Raw values are not carried and input is not passed across pages. Next-step links only open tool pages.
Specialized checks
- Waiting for analysis
Parsed without specialized checks
- Waiting for analysis
| Header | Value | State | Summary |
|---|---|---|---|
| Waiting for analysis | |||
Paste response headers, then analyze. This page does not request URLs or submit input to the backend.