Paste the response headers of a page — curl -sI https://your-site.example/
in a terminal, or the block from the browser Network panel — and get an
A+ to F grade on the OWASP Secure Headers checklist:
Strict-Transport-Security, Content-Security-Policy,
X-Content-Type-Options, framing protection, Referrer-Policy,
Permissions-Policy, the cross-origin isolation trio, version leaks,
deprecated headers and cookie flags — each finding paired with the exact
nginx, Apache and Express lines that fix it. Everything runs in your
browser; the page never contacts your site.
Response headers
The status line is optional. Multiple Set-Cookie lines are all
checked. To have a policy to grade in the first place, build one on the
CSP generator; to take a header block apart
line by line, use the HTTP header parser.
No grade yet. Paste response headers and press Check headers, or load a sample.
Findings
Fix it — copy the lines for your stack
Fix lines for every finding appear here after a check.
Scope of this checker versus the SSL Security Check.
This page grades the security response headers (the OWASP list
above). The SSL Security Check grades
your HTTPS setup: certificate chain, protocol versions, cipher
strength and mixed content. HSTS and cookie flags appear on both pages
because both lists include them, but with different lenses - run both
checks for the full picture.
Self-test
Re-runs the grader against fixed header blocks: the good sample at A+,
the bad sample at F with every deduction fired, each rule in isolation
(the arithmetic of the score), the version-leak cap, cookie advisories,
CSP quality notes, frame-ancestors counting as framing protection,
grade thresholds on both sides of every boundary, the fix snippets,
and the negative paths. Nothing is sent anywhere.
What are security headers?
In one sentence: security headers are response headers that
instruct the browser to enforce a protection it could not figure out
on its own — never load scripts from unknown origins, never
speak plain HTTP to this host again, never frame this page —
and they cost one configuration line each.
The headers this page grades
Header
Protects against
OWASP recommended value
Strict-Transport-Security
protocol downgrade and cookie theft on the first plain-HTTP request
pages and embeds silently using camera, mic, geolocation
all features disabled
Cross-Origin-Opener-Policy
other windows reaching into your browsing context
same-origin
Cross-Origin-Embedder-Policy
loading resources that did not opt in (enables process isolation)
require-corp
Cross-Origin-Resource-Policy
your resources embedded by other sites
same-origin
How the grade is computed
Start at 100 and subtract: −25 missing CSP, −20 missing HSTS, −10 each for missing X-Content-Type-Options, Referrer-Policy or any framing protection, −5 each for the cross-origin trio and Permissions-Policy, −5 for version leaks in Server/X-Powered-By (capped), and −5 for a non-zero X-XSS-Protection. Letter grades: 100 = A+, 90+ = A, 80+ = B, 70+ = C, 60+ = D, below = F. Advisory notes (cookie flags, cache control, CSP quality) do not subtract.
Common mistakes
Setting headers on the wrong responses. Add them on every response, including error pages and redirects - that is what the always in add_header ... always; (nginx) and Header always set (Apache) is for.
Testing only the homepage. Proxies, caches and legacy apps often strip or override headers on some paths only. Check the pages that matter: login, checkout, API endpoints.
Keeping X-XSS-Protection. The auditor it drove caused vulnerabilities of its own; browsers removed it. A non-zero value now costs score on purpose - remove it and let CSP do the job.
Believing X-Frame-Options is current. It cannot allow specific origins and is not in the CSP standard; frame-ancestors is the modern replacement. Keeping both during the transition is fine - this page accepts either.
Shipping version banners.Server: Apache/2.4.58 (Unix) narrows an attacker's search for known bugs at zero benefit. Strip the version; keep the line count down.
FAQ
Why is COOP/COEP/CORP only worth 5 points each? The trio is the newest layer, mainly needed where you want process isolation (SharedArrayBuffer, Spectre-hardening). A site without them still has its core protections; with them, some cross-origin embeds need adjustments - which is why they weigh less than CSP or HSTS.
Does a high grade mean the site is secure? No - it means the response headers are set. Security headers are one layer: TLS configuration, session handling, input validation and patching still decide whether the site is actually secure. Run the SSL Security Check for the TLS layer.
Why is my Permissions-Policy value so long? The OWASP baseline switches off every feature explicitly, so a browser adding new features does not silently re-enable them. A shorter value like camera=(), microphone=(), geolocation=() is a start - just know what it leaves on.
Can I check headers of any site from here? This page never makes network requests - it grades exactly the text you paste, so it works behind firewalls and on internal hosts, and nothing you inspect leaves your machine. Fetching the headers is one curl -sI in your terminal.
What about Clear-Site-Data and X-Permitted-Cross-Domain-Policies? Useful in narrow scenarios (logout responses; legacy PDF/Flash viewers). They are advisory here, not scored - sending Clear-Site-Data on every response would wipe your users' storage every page load.