Security Headers Score

Enter a URL — get a 0–100 security score with per-header breakdown and the exact fix for every issue. Every flag links directly to the exact fix — no searching for what to do next.

A
100
Excellent
Enter a URL above to scan

See also: Security headers score guide

Scans any URL and returns a 0-100 security score based on which HTTP security headers are present. Checks Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and COOP. Every failing header links directly to the fix.

You might also need
🔒HeadersFixer
Scan security headers and get stack-specific fixes
📋Pre-Launch Checklist
20 HTTP checks before you ship
CSP Validator
Validate your Content Security Policy against W3C spec
Done with this tool?
20 HTTP checks before you ship — security, CORS, cache, redirects, staging.
Pre-Launch Checklist →
📖 HttpFixer Blog — fix guides, explainers, and references →