Security Headers & CSP Analyzer

Paste a site’s response headers or its Content-Security-Policy and see what is missing, what is misconfigured and how to fix it — HSTS, CSP, framing, cookies, CORS and more.

Runs entirely in your browser. Your browser blocks this page from opening connections or loading anything from other sites. Nothing you enter is uploaded or saved.

requests since opened: 0
How to verify this yourself
  1. Open your browser’s developer tools (F12, or ⌥⌘I on Mac) → Network tab, then use the tool. No new requests appear.
  2. Or disconnect from the internet after the page loads — the tool keeps working, because it never needed the network.
  3. See the rule itself: in the Network tab, select this page’s document → Response Headers → content-security-policy contains connect-src 'none' and no 'unsafe-inline' for scripts.
  4. Press Test the lock: the page tries a harmless request and the browser blocks it (the Console shows the refusal).
How to use
  1. Paste the response headers (curl output or a DevTools copy), or just a policy — or use “Get the headers from a site” for a ready command.
  2. Read “Fix these” first, then the policy table and cookie flags.
  3. Copy the missing headers for your server, or the report for a ticket.
Examples:
Get the headers from a site

This page cannot connect to sites. Run this command, then paste its output in the box above. Or copy the response headers from your browser’s developer tools (Network tab → the page → Headers).

Common questions

How do I check a website’s security headers?

Run the command from “Get the headers from a site” (curl, on any OS) or copy the response headers from your browser’s developer tools, then paste them here. Nothing is sent anywhere: the page is locked so it cannot connect.

What makes a Content-Security-Policy weak?

Allowing 'unsafe-inline' scripts without a nonce, allowing whole schemes like https: or data:, or trusting public CDNs such as cdn.jsdelivr.net that serve anyone’s code. A nonce with 'strict-dynamic' avoids all three.

Do APIs need security headers?

Fewer of them. A JSON API should send HSTS and nosniff, and a tiny CSP (default-src 'none'; frame-ancestors 'none'). Switch “Check as” to API to see only the checks that matter.

Known limitations

  • No network: it checks the headers you paste, not the live site, and cannot see what the page loads or whether a nonce changes per response.
  • Header checks follow the specifications and current Chrome, Firefox and Safari behaviour; very old browsers may differ.
  • The CSP bypass list covers well-known public CDNs and shared hosting, not every risky host.
  • Cookie values and request headers (Cookie, Authorization) are dropped as they are read and never shown.
  • Browser extensions with access to this site can read the page. For sensitive data, use a private window with extensions off. How the lock works

tools v0.9.0 · build 7317bbb · 2026-10-07