thoughtasylumTOOLBOX Preview

Tools › Web

Security Headers & CSP

Paste a site’s response headers to have its security headers graded and explained, its Content Security Policy checked line by line, and its cookies’ flags checked. Build a new policy below.

About this tool What it's for, how to use it and an example

What it's for

Check the HTTP headers a site sends to protect its visitors: a Content Security Policy (CSP) that limits where scripts may come from, HSTS that keeps browsers on HTTPS, protection against being framed by other sites (clickjacking), and the flags on its cookies. Each is graded and explained, and a builder below makes a new policy.

For example, when a security scan or a client’s checklist asks for “security headers”, paste your site’s headers here to see which are missing and what to add.

How to use it

Get the headers with the curl -sI command shown (type the site’s address to fill it in), or copy them from the Network panel of the browser’s developer tools, and paste them. Lines from an nginx add_header or Apache Header set configuration work too. The table grades the six main headers (CSP, HSTS, frame protection, X-Content-Type-Options, Referrer-Policy and Permissions-Policy) from A+ to F, then notes others worth knowing, such as software versions and cookies without Secure, HttpOnly or SameSite. A policy is broken down directive by directive, with its weak points listed.

In Build a policy, fill in the sources each kind of content may come from; the header updates as you type and is checked the same way.

Example

Press Try an example. The headers include strict-transport-security: max-age=31536000; includeSubDomains, a policy with script-src 'self' 'unsafe-inline' https://cdn.example.net, x-content-type-options: nosniff, server: nginx/1.24.0 and a session cookie.

The message says Grade D: 2 of the 6 main security headers set well. The policy is marked weak because 'unsafe-inline' lets injected scripts run, X-Frame-Options is missing, the server version is noted, and the cookie is listed as without Secure and SameSite.

Good to know

It reads only what you paste: this page doesn’t fetch anything from the site. Headers can differ between pages and between the HTML and the files it loads, so check the pages that matter. A good grade isn’t a security review: a strict policy still needs testing, as it can stop parts of a site working.

Get the headers with curl -sI https://example.com, or copy them from the Network panel of the browser's developer tools.

Build a policy

Sources are separated by spaces, such as 'self' https://cdn.example.net. Leave a box empty to leave it out.

    Private: this tool runs in your browser. Nothing you type, paste or choose leaves this page.

    Saved you a few minutes? Say thanks with a coffee.

    Something wrong with this tool, or missing from it? Report a bug or suggest a feature.

    ↑ ↓ move↵ openesc close