Security Headers Checker
Paste a URL to analyze its HTTP security headers. The tool checks for Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, and other headers that protect against common web attacks. You'll get a grade and a list of missing protections.
returns
- data.grade
- Letter grade based on how many security headers are missing.
- data.missing
- Recommended security headers the site doesn't send.
- data.headers
- Every response header, keyed by lowercase name.
- data.status_code
- HTTP status the URL answered with.
- data.url
- The URL that was scanned.
Fill in the fields and send a request. The response lands here.
Run it from your code
A temporary key takes one request and lasts seven days at 20 calls a day. Register and it becomes 75 a day, still free.
$ curl -s "https://apixies.io/api/v1/inspect-headers?url=https://github.com" \ -H "X-API-Key: $APIXIES_KEY" | jq '.data.grade' "B"
questions
What security headers should every website have?
At minimum: Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options, and Referrer-Policy. These protect against XSS, clickjacking, MIME sniffing, and information leakage.
What does the security grade mean?
The grade reflects how many recommended security headers are present and correctly configured. An A means all critical headers are set. Lower grades indicate missing protections.