Security and networkingChecked through WebDiag API

Security Headers Checker

Enter a URL to check the core HTTP headers that reduce XSS, clickjacking, referrer leakage, and unsafe browser API exposure.

  • Single URL
  • HTTP headers
  • Security score
Online tool

Try the tool

Enter a URL: WebDiag will run a safe network check and show the result.

Page URL

Check result

After the check, HSTS, CSP, nosniff, frame protection, Referrer-Policy, Permissions-Policy, and practical advice will appear here.

Network check through backend

For HTTP/SEO tools, the URL is sent to the WebDiag API, where SSRF protection, DNS/IP policy, and redirect limits are applied.

Reviewed: 2026-07-17
01

How to use it

  1. 1

    Paste the page or domain address you need to check.

  2. 2

    Run the check and wait for the WebDiag API response.

  3. 3

    Review HSTS, CSP, nosniff, frame protection, Referrer-Policy, and Permissions-Policy.

02

What the tool can do

  • Safe header fetching through the backend with SSRF protection and redirect limits.
  • Shows the score, risk level, present headers, and missing headers.
  • Provides practical advice for HTTPS, CSP, HSTS, and browser hardening.
03

Common use cases

  • Check whether security headers were lost after CDN, nginx, middleware, or hosting changes.
  • Quickly see whether basic protection exists against clickjacking, MIME sniffing, and excessive referrer leakage.
  • Give a developer a compact missing-header list without manual DevTools inspection.
04

How it works inside

The result uses status, the final URL after redirects, and HTTP response headers; the page body is not downloaded.

Frame protection is considered present when X-Frame-Options or CSP frame-ancestors is available.

05

Questions and answers

Why can HSTS be a problem on HTTP?

HSTS only works on HTTPS responses. If the final URL remains HTTP, fix HTTPS and redirects first.

Does a high score mean the site is secure?

No. This checks basic browser security headers for one URL, not a pentest, SAST, or full security audit.