Free tool
Which security headers is your site missing?
Response headers are the cheapest security work there is: a handful of lines in a config file, and every one of them closes off an attack a browser would otherwise allow. We make one request to your homepage and report which are set, which are missing, and how much each one is worth.
What it actually does
Three steps, and none of them touch anything on the address you give it. Worth reading before you point a scanner at your own production site.
-
Step 1
One request
A single GET to the homepage. No crawl, no repeated requests, nothing that would show up as load.
-
Step 2
Read what came back
The response headers are graded against the published guidance for each one rather than against a house opinion.
-
Step 3
Report the gap
Which are set, which are missing, and what each missing one would have prevented.
Read-only. Nothing is signed in to, submitted or changed on the address you enter. See the methodology for how each result is graded.
The rest of it
This is one check of 48.
Headers are one section. The full scan also covers TLS, performance, SEO, accessibility, AI visibility and conversion.
Run the full free auditRun your first audit today
Start on the free plan, with enough searches to cover a city and enough audits to judge a shortlist. No card, and it does not expire.