HTTP Header Analyzer

Review Content Security Policy, HSTS, cookies, browser isolation headers, cache directives, and information disclosure without sending headers to a server.

Browser onlySecurity headersBest practices

Response headers

Paste raw HTTP response headers. An optional HTTP status line is supported.

HTTP response security

Inspect security-related HTTP response headers

HTTP response headers instruct browsers how to handle content, protect users, enforce security policies, and reduce common web application vulnerabilities.

Headers commonly reviewed

Analyze Content Security Policy (CSP), Strict-Transport-Security (HSTS), Referrer-Policy, Permissions-Policy, X-Frame-Options, X-Content-Type-Options, Cross-Origin policies, Cache-Control, and Set-Cookie attributes.

Improve security posture

Review missing headers, insecure cookie attributes, information disclosure, caching behavior, and browser protection mechanisms before deploying your application.

Guide

About HTTP Header Analyzer

HTTP response headers control browser security, caching, content handling, privacy, and cross-origin behavior.

This analyzer reviews pasted headers and highlights common missing, risky, or inconsistent settings.

Header analysis is only one part of application security and does not test server-side authorization or business logic.

Headers commonly reviewed

The analyzer focuses on browser-facing security and privacy controls.

  • Content-Security-Policy
  • Strict-Transport-Security
  • Referrer-Policy
  • Permissions-Policy
  • X-Content-Type-Options
  • COOP, COEP, and CORP

Cookie attributes

Secure, HttpOnly, SameSite, Domain, Path, and expiration attributes influence how browsers send and expose cookies.

Information disclosure

Server and framework headers can reveal implementation details that are unnecessary for clients.

Interpret findings in context

Some applications require exceptions. Test changes carefully and document why a header is absent or relaxed.

FAQ

Frequently asked questions

Which security headers are most important?

CSP, HSTS, secure cookie attributes, Referrer-Policy, and content-type protections are common priorities.

Does X-Frame-Options replace CSP frame-ancestors?

frame-ancestors is the modern CSP control, while X-Frame-Options remains useful for compatibility.

What does HSTS do?

HSTS instructs browsers to use HTTPS for a host for a specified period.

Why are cookie attributes important?

They reduce exposure to network interception, script access, and some cross-site request scenarios.

Does a good header report prove the application is secure?

No. Application logic, dependencies, APIs, and access controls require separate testing.

Are pasted headers uploaded?

Analysis is intended to occur locally in your browser.

Continue exploring

Useful tools for the next step in the same workflow.