HTTP Header Analyzer
Review Content Security Policy, HSTS, cookies, browser isolation headers, cache directives, and information disclosure without sending headers to a server.
Response headers
Paste raw HTTP response headers. An optional HTTP status line is supported.
HTTP response security
Inspect security-related HTTP response headers
HTTP response headers instruct browsers how to handle content, protect users, enforce security policies, and reduce common web application vulnerabilities.
Headers commonly reviewed
Analyze Content Security Policy (CSP), Strict-Transport-Security (HSTS), Referrer-Policy, Permissions-Policy, X-Frame-Options, X-Content-Type-Options, Cross-Origin policies, Cache-Control, and Set-Cookie attributes.
Improve security posture
Review missing headers, insecure cookie attributes, information disclosure, caching behavior, and browser protection mechanisms before deploying your application.
Guide
About HTTP Header Analyzer
HTTP response headers control browser security, caching, content handling, privacy, and cross-origin behavior.
This analyzer reviews pasted headers and highlights common missing, risky, or inconsistent settings.
Header analysis is only one part of application security and does not test server-side authorization or business logic.
Headers commonly reviewed
The analyzer focuses on browser-facing security and privacy controls.
- Content-Security-Policy
- Strict-Transport-Security
- Referrer-Policy
- Permissions-Policy
- X-Content-Type-Options
- COOP, COEP, and CORP
Cookie attributes
Secure, HttpOnly, SameSite, Domain, Path, and expiration attributes influence how browsers send and expose cookies.
Information disclosure
Server and framework headers can reveal implementation details that are unnecessary for clients.
Interpret findings in context
Some applications require exceptions. Test changes carefully and document why a header is absent or relaxed.
FAQ
Frequently asked questions
Which security headers are most important?
CSP, HSTS, secure cookie attributes, Referrer-Policy, and content-type protections are common priorities.
Does X-Frame-Options replace CSP frame-ancestors?
frame-ancestors is the modern CSP control, while X-Frame-Options remains useful for compatibility.
What does HSTS do?
HSTS instructs browsers to use HTTPS for a host for a specified period.
Why are cookie attributes important?
They reduce exposure to network interception, script access, and some cross-site request scenarios.
Does a good header report prove the application is secure?
No. Application logic, dependencies, APIs, and access controls require separate testing.
Are pasted headers uploaded?
Analysis is intended to occur locally in your browser.
Continue exploring
Related tools
Useful tools for the next step in the same workflow.
CSP Builder
Build and review Content Security Policy headers.
Website Security
Website Security Scanner
Inspect HTTPS, TLS, headers, cookies, and common security configuration issues.
Website Security
SRI Hash Generator
Generate and verify integrity hashes for scripts and stylesheets.
Cryptography
SSL/TLS Checker
Inspect a live server's TLS protocol, cipher, certificate chain, expiration, and trust status.
Website Security
X.509 Certificate Decoder
Decode certificate identity, validity, algorithms, key details, and fingerprints locally.
PKI & Certificates
CSR Decoder
Decode PKCS#10 certificate signing requests and review requested identities, keys, and extensions.
PKI & Certificates