How to use it
- 1
Paste the page or domain address you need to check.
- 2
Run the check and wait for the WebDiag API response.
- 3
Review HSTS, CSP, nosniff, frame protection, Referrer-Policy, and Permissions-Policy.
What the tool can do
- Safe header fetching through the backend with SSRF protection and redirect limits.
- Shows the score, risk level, present headers, and missing headers.
- Provides practical advice for HTTPS, CSP, HSTS, and browser hardening.
Common use cases
- Check whether security headers were lost after CDN, nginx, middleware, or hosting changes.
- Quickly see whether basic protection exists against clickjacking, MIME sniffing, and excessive referrer leakage.
- Give a developer a compact missing-header list without manual DevTools inspection.
How it works inside
The result uses status, the final URL after redirects, and HTTP response headers; the page body is not downloaded.
Frame protection is considered present when X-Frame-Options or CSP frame-ancestors is available.
Questions and answers
Why can HSTS be a problem on HTTP?
HSTS only works on HTTPS responses. If the final URL remains HTTP, fix HTTPS and redirects first.
Does a high score mean the site is secure?
No. This checks basic browser security headers for one URL, not a pentest, SAST, or full security audit.
