HTTP Security Header Analyzer
Analyze raw HTTP response headers and surface missing or weak HSTS, CSP, X-Frame-Options, and other browser security protections. Free by Graph Tools.
Use this free HTTP security header analyzer to check raw response headers for missing or misconfigured browser security protections. The tool evaluates HSTS strength and max-age, CSP presence, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy directives against current best practices. Paste any set of response headers and get a graded report with recommendations. Useful for web security auditors, frontend developers, and DevOps engineers.