Skip to content

Free tool

Which security headers is your site missing?

Response headers are the cheapest security work there is: a handful of lines in a config file, and every one of them closes off an attack a browser would otherwise allow. We make one request to your homepage and report which are set, which are missing, and how much each one is worth.

Free, no account, and read-only

What it actually does

Three steps, and none of them touch anything on the address you give it. Worth reading before you point a scanner at your own production site.

  1. Step 1

    One request

    A single GET to the homepage. No crawl, no repeated requests, nothing that would show up as load.

  2. Step 2

    Read what came back

    The response headers are graded against the published guidance for each one rather than against a house opinion.

  3. Step 3

    Report the gap

    Which are set, which are missing, and what each missing one would have prevented.

Read-only. Nothing is signed in to, submitted or changed on the address you enter. See the methodology for how each result is graded.

The rest of it

This is one check of 48.

Headers are one section. The full scan also covers TLS, performance, SEO, accessibility, AI visibility and conversion.

Run the full free audit

Run your first audit today

Start on the free plan, with enough searches to cover a city and enough audits to judge a shortlist. No card, and it does not expire.