Loading...
Grade HTTP response headers against the OWASP secure-header baseline — HSTS, CSP, cookie flags, MIME-sniffing, clickjacking — with fixes.
Tip: curl -sI https://example.com prints exactly this block. Nothing leaves your browser.
Paste a response header block to grade it against the OWASP secure-header baseline (HSTS, CSP, cookies, MIME-sniffing, clickjacking, and info disclosure).