Security Headers Analyzer
A response-header diagnostic workbench — HSTS, CSP, clickjacking protection, and cross-origin isolation, with a transparent score. No account required.
HTTP Security Header Diagnostic
Request
Response
Header Inspection
CSP Analysis
Security Posture
This tool performs a single external HTTP request to the public website you submit — it does not authenticate to the target, scan private or internal networks, or perform a penetration test. IT KORR's own domains and infrastructure cannot be scanned with this tool.
What This Tool Checks
Nine HTTP Security Headers
Each header is evaluated individually — presence, observed value, and common weak configurations — not lumped into a single pass/fail.
Strict-Transport-Security
Forces browsers to only connect over HTTPS, closing the window for downgrade attacks on the first request.
Content-Security-Policy
Restricts which sources scripts and other resources can load from, reducing XSS impact.
X-Content-Type-Options
Prevents older browsers from guessing a resource's content type in a way that can be abused.
X-Frame-Options / frame-ancestors
Prevents this site from being embedded in a hidden iframe — the basis of clickjacking.
Referrer-Policy
Controls how much of this site's URL is shared with other sites via the referrer.
Permissions-Policy
Explicitly disables browser features (camera, geolocation, etc.) a site doesn't use.
Cross-Origin-Opener-Policy
Isolates this site's browsing context from cross-origin popups and windows.
Cross-Origin-Resource-Policy
Controls whether other origins may load this site's resources directly.
Cross-Origin-Embedder-Policy
Requires embedded cross-origin resources to explicitly opt in, enabling stronger isolation.
Understanding Your Score
A Transparent Score, Not a Security Verdict
Every point in the score is tied to a specific header check shown in the results — there is no hidden weighting. The score reflects only the HTTP response-header checks this tool performs; it is not a complete website security rating, and this tool does not perform a penetration test. Use it as one input into a broader security review, not a final verdict.
FAQ
Common Questions
What does this tool actually check?
It makes a single external HTTP request to the public URL you submit and inspects the response headers for Strict-Transport-Security (HSTS), Content-Security-Policy (CSP), X-Content-Type-Options, X-Frame-Options (and CSP frame-ancestors), Referrer-Policy, Permissions-Policy, and the three Cross-Origin-* isolation headers.
Does a high score mean this website is secure?
No. The score reflects only the HTTP response-header checks this tool performs — it is not a complete website security rating, a vulnerability scan, or a penetration test. A site can score well here and still have unrelated security issues, and a lower score here does not necessarily mean the site is actively vulnerable.
Why does this tool flag CSP as "needs attention" even though the header is present?
CSP evaluation is genuinely complex, and this tool checks for a few common weak patterns — such as 'unsafe-inline' or 'unsafe-eval' in the policy — rather than performing a full policy audit. A CSP header that includes these directives still provides some protection, but meaningfully less than a tightly scoped one.
Is missing "preload" on my HSTS header treated as a failure?
No. HSTS preload submission is optional and has real tradeoffs — once a domain is preloaded into browsers, removing it is slow and difficult. This tool does not penalize a strong HSTS configuration for omitting preload.
Can this tool scan IT KORR's own website or internal/private networks?
No. IT KORR domains and infrastructure are blocked at the platform level, and only publicly routable internet targets can be inspected — private, internal, loopback, link-local, and reserved address ranges are all rejected before any request is made.
Does this tool download or store the target website's content?
No. It reads only the HTTP response status and headers for a single request — the response body is never downloaded, and nothing about the target is stored after your results are shown.
Related Tools & Services
Trace the full redirect chain for any public URL.
Inspect certificate validity, expiration, and TLS version for any domain.
Full DNS diagnostic including MX routing and email authentication records.
Get a comprehensive security assessment beyond HTTP headers.
Operational Support
Need a deeper security review than HTTP headers?
IT KORR can perform a comprehensive security assessment covering configuration, identity, endpoints, and more — not just externally visible headers.
No commitment required — we respond within one business day.