Security Headers & CSP Analyzer
Paste a site’s response headers or its Content-Security-Policy and see what is missing, what is misconfigured and how to fix it — HSTS, CSP, framing, cookies, CORS and more.
How to use
- Paste the response headers (curl output or a DevTools copy), or just a policy — or use “Get the headers from a site” for a ready command.
- Read “Fix these” first, then the policy table and cookie flags.
- Copy the missing headers for your server, or the report for a ticket.
Get the headers from a site
This page cannot connect to sites. Run this command, then paste its output in the box above. Or copy the response headers from your browser’s developer tools (Network tab → the page → Headers).
Common questions
How do I check a website’s security headers?
Run the command from “Get the headers from a site” (curl, on any OS) or copy the response headers from your browser’s developer tools, then paste them here. Nothing is sent anywhere: the page is locked so it cannot connect.
What makes a Content-Security-Policy weak?
Allowing 'unsafe-inline' scripts without a nonce, allowing whole schemes like https: or data:, or trusting public CDNs such as cdn.jsdelivr.net that serve anyone’s code. A nonce with 'strict-dynamic' avoids all three.
Do APIs need security headers?
Fewer of them. A JSON API should send HSTS and nosniff, and a tiny CSP (default-src 'none'; frame-ancestors 'none'). Switch “Check as” to API to see only the checks that matter.
Known limitations
- No network: it checks the headers you paste, not the live site, and cannot see what the page loads or whether a nonce changes per response.
- Header checks follow the specifications and current Chrome, Firefox and Safari behaviour; very old browsers may differ.
- The CSP bypass list covers well-known public CDNs and shared hosting, not every risky host.
- Cookie values and request headers (Cookie, Authorization) are dropped as they are read and never shown.
- Browser extensions with access to this site can read the page. For sensitive data, use a private window with extensions off. How the lock works
Related reading on CipherMind
Standards & references
- W3C Content Security Policy Level 3 (opens in a new tab)
- RFC 6797 — HTTP Strict Transport Security (opens in a new tab)
- OWASP HTTP Headers Cheat Sheet (opens in a new tab)
- Google — strict CSP (nonces and strict-dynamic) (opens in a new tab)
- RFC 6265bis — cookies (SameSite, prefixes) (opens in a new tab)
- Fetch standard — CORS (opens in a new tab)
- W3C Permissions Policy (opens in a new tab)