HTTP Headers Analyzer
Explain headers and audit CORS, CSP, and browser security controls locally.
HTTP headersOne Header-Name: value per line
content-security-policymissingNo CSP was supplied in the pasted headers.
strict-transport-securitymissingNo HSTS policy was supplied.
x-content-type-optionsmissingUse X-Content-Type-Options: nosniff.
x-frame-optionsmissingReview frame embedding protection.
referrer-policymissingConsider an explicit referrer policy for sensitive applications.
permissions-policymissingConsider an explicit Permissions-Policy for browser capabilities.