Security Headers Badge
A simple, documented count: A2Z checks your home page for six widely recommended security headers and shows how many are present. The public report lists exactly which ones are missing, with the raw values that were received.
Live preview
Checked live by A2ZShowing the badge for a2z.tools. Enter your domain to see yours.
Embed code
The badge is re-checked automatically (every few hours; every 5 minutes for website status) and cached, so it adds almost nothing to your page load. The link carries rel="nofollow".
Works with
How it works
A2Z loads https://your-domain/ (following redirects) and looks for six response headers: Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options set to nosniff, X-Frame-Options or a CSP frame-ancestors directive, Referrer-Policy and Permissions-Policy. Each present header counts one point. The badge prints the count rather than a letter grade, so it cannot overstate what was found, and X-XSS-Protection is deliberately not counted because current guidance is to leave it out.
What is checked
- Score = number of the six headers present on the final HTTPS response of the home page
- X-Content-Type-Options counts only with the value nosniff; X-Frame-Options and CSP frame-ancestors count as one item
- Green at 5-6, amber at 3-4, red at 0-2; presence is checked, not the strength of each policy
Limitations
- Presence only: a permissive Content-Security-Policy counts the same as a strict one.
- Pages served by a different application or path can send different headers.
- Does not evaluate cookies, CORS or the site's own code.
Where publishers use it
- Developer portfolios and open-source project sites
- Agencies reporting hardening work to clients
- Security teams tracking header rollout across many domains
Questions
Does 6 / 6 mean my site is secure?
No. It means six recommended headers are present. A weak Content-Security-Policy still counts as present - the report shows the raw values so you can judge them yourself.
Why only the home page?
Headers are usually set site-wide by the server or CDN, so the home page is representative. Pages produced by a different application may differ, and the badge cannot see them.
Why is X-XSS-Protection not counted?
Modern browsers ignore it and OWASP's current guidance is to omit it, so counting it would reward an obsolete header.
Sources
- OWASP Secure Headers Project - OWASP Foundation . Which response headers to send and which are obsolete.
- Content Security Policy Level 3 - W3C . Includes the frame-ancestors directive.
- RFC 7034 - HTTP header field X-Frame-Options - IETF
- Fetch Standard - X-Content-Type-Options - WHATWG
- Referrer Policy - W3C
- Permissions Policy - W3C
- RFC 6797 - HTTP Strict Transport Security (HSTS) - IETF
Cite or recommend this tool
If you reference this tool in an article, course or documentation, these formats are ready to copy. They are optional - nothing is added to your site unless you paste it.
A2Z Tools Security Headers Badge https://a2z.tools/security-headers-checker
<a href="https://a2z.tools/security-headers-checker">A2Z Tools Security Headers Badge</a>
[A2Z Tools Security Headers Badge](https://a2z.tools/security-headers-checker)
Security Headers Badge by A2Z Tools - https://a2z.tools/security-headers-checker
Related widgets
-
Shows whether your site sends HTTP Strict Transport Security, with max-age and preload.
-
Visitors enter a domain and see which of six key security headers it sends.
-
Shows whether your site serves HTTPS and redirects plain-HTTP visitors to it.
-
A live badge showing that your SSL certificate is valid, trusted and how many days it has left.
-
A badge counting down the days until your SSL certificate expires.
-
Shows whether your domain publishes an SPF record and how it ends (-all, ~all).