RunTheTest

Security Headers Checker

Analyze CSP, HSTS, X-Frame-Options and other security headers

Security Headers Reference

Content-Security-Policy

Prevents XSS attacks by controlling which resources can be loaded.

Strict-Transport-Security

Forces HTTPS connections and prevents downgrade attacks.

X-Frame-Options

Prevents clickjacking by controlling iframe embedding.

X-Content-Type-Options

Prevents MIME type sniffing attacks.

Referrer-Policy

Controls how much referrer information is sent with requests.

Permissions-Policy

Controls which browser features can be used.