Free tool · no sign-up

Free security headers checker

Security headers are small settings that tell browsers to block common attacks such as clickjacking and malicious scripts. See which ones your site sends, and how its cookies are protected.

We make a few ordinary requests, like one visitor opening your home page. Results are not stored.

Check everything at once

This tool looks at one area. The full website security scan also checks SSL, email spoofing protection, exposed files and outdated software, and gives you a score and a fix plan.

Free Security Watch

Keep an eye on your website, free

  • A short re-scan summary by email once a month: your score, what changed and the top issues.
  • A reminder 21 and 7 days before your SSL certificate expires.
  • A reminder 30 days before your domain registration expires, when the registry publishes the date.

Up to 3 websites per email address. Unsubscribe with one click from any email. Need weekly scans, every finding and instant alerts? See Monitoring (AED 1,199 / year).

We will email you a link to confirm. Nothing is sent until you click it.

Questions about the Security Headers Checker

Which security headers matter most?

Strict-Transport-Security (forces HTTPS), Content-Security-Policy (limits where scripts can load from), X-Frame-Options or CSP frame-ancestors (stops clickjacking) and X-Content-Type-Options. Referrer-Policy and Permissions-Policy add privacy and limit browser features.

Can adding headers break my website?

Most cannot. Content-Security-Policy can block scripts your site relies on, so start it in report-only mode or test it on a staging copy first. HSTS should be added only once HTTPS works everywhere on the domain.

Where do I add these headers?

In your web server configuration (.htaccess on Apache/cPanel, the server block on Nginx), in a CDN such as Cloudflare, or with a security plugin on WordPress. The full scan report includes copy-paste snippets for each.

Why are cookie flags included?

Cookies without the Secure, HttpOnly and SameSite flags are easier to steal or misuse. The checker looks at the cookies your home page sets.