---
title: "Security Headers Analyzer"
description: "Paste a site's HTTP response headers and get a security grade. Checks Content-Security-Policy, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy and the Cross-Origin headers. Nothing is fetched."
url: https://findutils.com/network/security-headers-analyzer/
category: network
---

# Security Headers Analyzer

Paste a site's HTTP response headers and get a security grade. Checks Content-Security-Policy, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy and the Cross-Origin headers. Nothing is fetched.

**Use this tool:** [Security Headers Analyzer](https://findutils.com/network/security-headers-analyzer/)

## Programmatic access

- REST id `security-headers-analyzer`: POST https://api.findutils.com/api/tools/security-headers-analyzer/execute (reference: https://findutils.com/api/security-headers-analyzer/)
- MCP tool `security_headers_analyzer` on https://mcp.findutils.com (reference: https://findutils.com/mcp/security-headers-analyzer/)

## Why Check Security Headers?

Security headers are your first line of defense against common web attacks. They protect against XSS, clickjacking, MIME sniffing, and other vulnerabilities.

## Security Headers Best Practices

- Start with Content-Security-Policy in report-only mode to log violations before enforcing rules, preventing accidental breakage of scripts or styles on your site.
- Set Strict-Transport-Security with a max-age of at least one year (31536000 seconds) and include the includeSubDomains and preload directives for full HSTS coverage.
- Always pair X-Content-Type-Options: nosniff with correct Content-Type headers on all responses to prevent browsers from guessing MIME types incorrectly.
- Use Permissions-Policy to explicitly disable browser features you do not use, such as camera, microphone, and geolocation, reducing your attack surface.
- Combine X-Frame-Options with CSP frame-ancestors for backward compatibility. Modern browsers respect frame-ancestors, while older browsers fall back to X-Frame-Options.

## Frequently Asked Questions

### What are HTTP security headers?

Security headers are HTTP response headers that instruct browsers how to handle your website's content, protecting against various attack vectors.

### Which headers are most important?

Content-Security-Policy and Strict-Transport-Security are crucial. X-Frame-Options, X-Content-Type-Options, and Referrer-Policy are also highly recommended.

### Will adding headers break my site?

Some headers like CSP need careful configuration. Start with report-only mode to identify issues before enforcing policies.

### How do I add security headers?

Headers can be added via web server configuration (Apache, Nginx), application code, or CDN settings depending on your setup.

### What is Content-Security-Policy and why is it critical?

Content-Security-Policy (CSP) is an HTTP header that controls which resources a browser is allowed to load on a page. It is the most effective defense against cross-site scripting (XSS) attacks because it restricts inline scripts, unauthorized script sources, and unsafe eval calls.

### What does Strict-Transport-Security (HSTS) do?

HSTS tells browsers to only connect to your site over HTTPS, even if a user types http:// in the address bar. It prevents protocol downgrade attacks and cookie hijacking. A recommended value is max-age=31536000 with includeSubDomains and preload directives.

### How often should I check my security headers?

You should scan your headers after every deployment, server configuration change, or CDN update. Automated weekly scans are recommended as part of a continuous security monitoring process. Header configurations can silently change when infrastructure is updated.

### Do security headers affect SEO or site performance?

Security headers have no negative impact on page load speed. In fact, Google considers HTTPS (enforced by HSTS) a ranking signal. Properly configured headers signal a trustworthy site to both search engines and visitors.

### What is the difference between X-Frame-Options and CSP frame-ancestors?

Both prevent clickjacking by controlling whether a page can be embedded in an iframe. X-Frame-Options is the older header with limited options (DENY, SAMEORIGIN). CSP frame-ancestors is more flexible, supports multiple origins, and is the recommended modern replacement.

### Can I test security headers without deploying to production?

Yes. You can test headers on staging or development environments. Many web servers and CDNs let you add headers to specific environments. Use report-only mode for Content-Security-Policy to log violations without blocking resources during testing.

### Why do I paste headers instead of entering a URL?

Because a web page cannot read another site's response headers. The browser's same-origin policy blocks it, so any tool that grades a URL from the browser is either guessing or sending your URL to a third-party proxy. This page grades the block you copy from curl -I or DevTools, and the REST and MCP versions take exactly the same input.

### What leaves my device when I use this tool?

Nothing. The headers you paste are graded in your browser by the same code the API uses; the page makes no request to the site you are checking or to FindUtils. The block you paste is never uploaded, stored, or logged, so headers from a staging or internal host are safe to check here.

## Related Tools

- [CSP Header Generator](https://findutils.com/security/csp-header-generator/)
- [SSL Certificate Checker](https://findutils.com/network/ssl-certificate-checker/)
- [URL Safety Checker](https://findutils.com/security/url-safety-checker/)
- [DNS Security Scanner](https://findutils.com/network/dns-security-scanner/)
- [Cookie Analyzer](https://findutils.com/security/cookie-analyzer/)
- [DNS Lookup](https://findutils.com/network/dns-lookup/)
- [Email Security Checker](https://findutils.com/security/email-security-checker/)
- [Privacy Policy Checker](https://findutils.com/security/privacy-policy-checker/)
- [JWT Security Validator](https://findutils.com/security/jwt-security-validator/)
