Security Headers Badge

A simple, documented count: A2Z checks your home page for six widely recommended security headers and shows how many are present. The public report lists exactly which ones are missing, with the raw values that were received.

Website & Security SVG badge Checked by A2Z server Free · no ads

Customize your badge

The badge is checked for this domain. Enter the site you will show it on.
Style
Colours
Size

Live preview

Checked live by A2Z
Security Headers Badge for a2z.tools

Showing the badge for a2z.tools. Enter your domain to see yours.

Embed code

The badge is re-checked automatically (every few hours; every 5 minutes for website status) and cached, so it adds almost nothing to your page load. The link carries rel="nofollow".

Works with

How it works

A2Z loads https://your-domain/ (following redirects) and looks for six response headers: Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options set to nosniff, X-Frame-Options or a CSP frame-ancestors directive, Referrer-Policy and Permissions-Policy. Each present header counts one point. The badge prints the count rather than a letter grade, so it cannot overstate what was found, and X-XSS-Protection is deliberately not counted because current guidance is to leave it out.

What is checked

  • Score = number of the six headers present on the final HTTPS response of the home page
  • X-Content-Type-Options counts only with the value nosniff; X-Frame-Options and CSP frame-ancestors count as one item
  • Green at 5-6, amber at 3-4, red at 0-2; presence is checked, not the strength of each policy

Limitations

  • Presence only: a permissive Content-Security-Policy counts the same as a strict one.
  • Pages served by a different application or path can send different headers.
  • Does not evaluate cookies, CORS or the site's own code.

Where publishers use it

  • Developer portfolios and open-source project sites
  • Agencies reporting hardening work to clients
  • Security teams tracking header rollout across many domains

Questions

Does 6 / 6 mean my site is secure?

No. It means six recommended headers are present. A weak Content-Security-Policy still counts as present - the report shows the raw values so you can judge them yourself.

Why only the home page?

Headers are usually set site-wide by the server or CDN, so the home page is representative. Pages produced by a different application may differ, and the badge cannot see them.

Why is X-XSS-Protection not counted?

Modern browsers ignore it and OWASP's current guidance is to omit it, so counting it would reward an obsolete header.

Sources

  1. OWASP Secure Headers Project - OWASP Foundation . Which response headers to send and which are obsolete.
  2. Content Security Policy Level 3 - W3C . Includes the frame-ancestors directive.
  3. RFC 7034 - HTTP header field X-Frame-Options - IETF
  4. Fetch Standard - X-Content-Type-Options - WHATWG
  5. Referrer Policy - W3C
  6. Permissions Policy - W3C
  7. RFC 6797 - HTTP Strict Transport Security (HSTS) - IETF

Cite or recommend this tool

If you reference this tool in an article, course or documentation, these formats are ready to copy. They are optional - nothing is added to your site unless you paste it.

A2Z Tools Security Headers Badge
https://a2z.tools/security-headers-checker

Preview