Security Headers Checker Widget
An embeddable security-headers test: enter a domain and see which of Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy and Permissions-Policy its home page sends, plus the details of its HSTS header.
Live preview
Exactly what your visitors will seeUnder the widget on your page: Powered by A2Z Tools
Embed code
<iframe src="https://a2z.tools/embed/w/security-headers-checker" title="Security Headers Checker by A2Z Tools" width="100%" height="520" style="border:0;width:100%" loading="lazy" allow="clipboard-write"></iframe>
A plain iframe. Works everywhere, including site builders that strip scripts. Adjust height if your content needs more room.
<div data-a2z-widget="security-headers-checker" data-height="520"></div> <script async src="https://a2z.tools/embed.js"></script>
Adds a small script (what it does) that sizes the widget to fit its content, loads it lazily and keeps it isolated from your page's CSS.
Works with
How it works
The widget asks A2Z to load the domain's home page over HTTPS, following redirects, and reports each of the six headers as present or missing - the same documented count as the security headers badge - together with a separate HSTS reading of max-age, includeSubDomains and preload. Each line carries an OK or Attention label as well as colour, and the linked report shows the raw header values so a reader can judge a policy's strength, which the count itself does not attempt.
What is checked
- Six headers checked on the final HTTPS response; each present header counts one (X-Frame-Options or CSP frame-ancestors count once)
- HSTS parsed per RFC 6797: max-age under 180 days reported as short
- Presence is checked, not the strength of each policy
Worked examples
A hardened site
Inputs: Home page sends HSTS (1 year), a CSP with frame-ancestors 'none', nosniff, Referrer-Policy and Permissions-Policy
Result: OK - 6 / 6; HSTS: enabled
frame-ancestors in the CSP stands in for X-Frame-Options.
A typical CMS site
Inputs: Home page sends only Strict-Transport-Security
Result: Problem - 1 / 6; five headers listed as missing
Most of the missing headers can be added at the web server or CDN without code changes.
Limitations
- Home page only; other applications on the same domain may differ.
- A permissive policy counts the same as a strict one.
- Cookies, CORS and application code are out of scope.
Where publishers use it
- Web security courses and tutorials
- Developer documentation for hardening guides
- Agencies' free-tools pages
Questions
Does a Content-Security-Policy-Report-Only header count?
No. Report-only mode logs violations without blocking anything, so it is reported as missing. It is a sensible step while you test a policy before enforcing it.
Is a CSP set in an HTML meta tag counted?
No. The check reads HTTP response headers only. A meta-tag policy cannot use frame-ancestors or reporting, which is one reason the header form is preferred.
Why is my CSP counted when it is permissive?
The check reports presence. A permissive policy is still a policy - review its content in the full report and tighten it over time.
Are results cached?
Yes, for six hours per domain, so the result may lag a header change by a few hours.
Which headers does it deliberately ignore?
X-XSS-Protection and Expect-CT, because current browsers ignore them and OWASP recommends against relying on them.
Sources
- OWASP Secure Headers Project - OWASP Foundation . Which response headers to send and which are obsolete.
- Content Security Policy Level 3 - W3C . Includes the frame-ancestors directive.
- RFC 7034 - HTTP header field X-Frame-Options - IETF
- Fetch Standard - X-Content-Type-Options - WHATWG
- Referrer Policy - W3C
- Permissions Policy - W3C
- RFC 6797 - HTTP Strict Transport Security (HSTS) - IETF
Cite or recommend this tool
If you reference this tool in an article, course or documentation, these formats are ready to copy. They are optional - nothing is added to your site unless you paste it.
A2Z Tools Security Headers Checker https://a2z.tools/security-headers-checker
<a href="https://a2z.tools/security-headers-checker">A2Z Tools Security Headers Checker</a>
[A2Z Tools Security Headers Checker](https://a2z.tools/security-headers-checker)
Security Headers Checker by A2Z Tools - https://a2z.tools/security-headers-checker
Related widgets
-
Counts how many of six key HTTP security headers your site sends - e.g. "5 / 6".
-
Let visitors check any domain's SSL certificate: validity, expiry, issuer and trust.
-
Shows whether your site sends HTTP Strict Transport Security, with max-age and preload.
-
A live badge showing that your SSL certificate is valid, trusted and how many days it has left.
-
A badge counting down the days until your SSL certificate expires.
-
Shows whether your site serves HTTPS and redirects plain-HTTP visitors to it.