How to use it
- 1
Paste an HTML, CSS, JS, image, or font URL.
- 2
Run the header check without downloading the response body.
- 3
Review score, cache directives, validators, and Vary policy.
What the tool can do
- Detects static assets by URL/content-type and applies a different evaluation standard than for HTML.
- Checks Cache-Control, validators, Expires fallback, and Vary: Accept-Encoding.
- Runs through SafeHttpFetcher with SSRF protection and read_body=false.
Common use cases
- Verify that hashed CSS/JS/fonts use long-lived immutable caching.
- Find HTML with risky long public caching.
- Check whether validators exist for revalidation.
How it works inside
The final response body is not downloaded; status, final URL, and headers are used.
Static asset heuristics use both URL extension and content-type.
Questions and answers
Should every file use max-age=31536000?
No. Long immutable caching is safe for content-hashed assets. HTML and non-personalized pages need rules that account for purge and releases.
Why does Vary matter?
With compression or content negotiation, Vary helps caches avoid mixing incompatible response variants.
