HTTP security headers scanner

Paste HTTP headers and find missing security headers such as HSTS, CSP, and X-Frame-Options.

{{ httpSecurityHeadersScanner.message }}

Overview

Quick check for HTTP response hardening in web apps and APIs.

Tool guide

  • O que são headers de segurança Cabeçalhos de resposta HTTP que reduzem riscos como clickjacking, MIME sniffing e downgrade de transporte.
  • O que a ferramenta manipula Bloco de headers HTTP colado manualmente (como os retornados por navegador, proxy ou API client).
  • O que a ferramenta faz Verifica presença e qualidade mínima de cabeçalhos como HSTS, CSP, X-Frame-Options, X-Content-Type-Options e Referrer-Policy.
  • Por que usar Hardening rápido de frontend/backend, revisão de deploy e checklist técnico de segurança antes de publicar mudanças.

Example

Strict-Transport-Security: max-age=31536000
X-Frame-Options: SAMEORIGIN

FAQ

What is this tool for?

It runs fully in your browser: useful to validate, format, or convert data in everyday development.

Are my inputs sent to a server?

Processing happens locally with JavaScript. We do not store what you paste into the text areas.

Can I use this for real production data?

Use at your own risk. For secrets (passwords, tokens), prefer controlled environments and your company policies. And always review the generated contents. Never trust blindly things you see on the internet.