← back to projects

Security Headers Scanner

Grades any site's HTTP security headers — CSP, HSTS, X-Frame-Options, and more — with weighted scoring and per-header explanations. Fetching happens server-side, hardened against SSRF (private/reserved IP blocking, standard ports only, redirect revalidation).

view source on GitHub ↗

$ headers//scan

grades a site's HTTP security headers — CSP, HSTS, framing, sniffing, referrer & permissions policy

>