Security Headers Checker Widget

An embeddable security-headers test: enter a domain and see which of Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy and Permissions-Policy its home page sends, plus the details of its HSTS header.

Website & Security Live check Checked by A2Z server Free · no ads

Customize your widget

Theme
Auto follows the visitor's light/dark setting.
Style
Attribution on your page
Optional and entirely your choice. The exact line is shown in the code below; it links to the tool with rel="nofollow".
More options
Starting values
Leave blank to use the widget's defaults. Visitors can still change every value.

Live preview

Exactly what your visitors will see

Embed code

<iframe src="https://a2z.tools/embed/w/security-headers-checker" title="Security Headers Checker by A2Z Tools" width="100%" height="520" style="border:0;width:100%" loading="lazy" allow="clipboard-write"></iframe>

A plain iframe. Works everywhere, including site builders that strip scripts. Adjust height if your content needs more room.

Works with

How it works

The widget asks A2Z to load the domain's home page over HTTPS, following redirects, and reports each of the six headers as present or missing - the same documented count as the security headers badge - together with a separate HSTS reading of max-age, includeSubDomains and preload. Each line carries an OK or Attention label as well as colour, and the linked report shows the raw header values so a reader can judge a policy's strength, which the count itself does not attempt.

What is checked

  • Six headers checked on the final HTTPS response; each present header counts one (X-Frame-Options or CSP frame-ancestors count once)
  • HSTS parsed per RFC 6797: max-age under 180 days reported as short
  • Presence is checked, not the strength of each policy

Worked examples

A hardened site

Inputs: Home page sends HSTS (1 year), a CSP with frame-ancestors 'none', nosniff, Referrer-Policy and Permissions-Policy

Result: OK - 6 / 6; HSTS: enabled

frame-ancestors in the CSP stands in for X-Frame-Options.

A typical CMS site

Inputs: Home page sends only Strict-Transport-Security

Result: Problem - 1 / 6; five headers listed as missing

Most of the missing headers can be added at the web server or CDN without code changes.

Limitations

  • Home page only; other applications on the same domain may differ.
  • A permissive policy counts the same as a strict one.
  • Cookies, CORS and application code are out of scope.

Where publishers use it

  • Web security courses and tutorials
  • Developer documentation for hardening guides
  • Agencies' free-tools pages

Questions

Does a Content-Security-Policy-Report-Only header count?

No. Report-only mode logs violations without blocking anything, so it is reported as missing. It is a sensible step while you test a policy before enforcing it.

Is a CSP set in an HTML meta tag counted?

No. The check reads HTTP response headers only. A meta-tag policy cannot use frame-ancestors or reporting, which is one reason the header form is preferred.

Why is my CSP counted when it is permissive?

The check reports presence. A permissive policy is still a policy - review its content in the full report and tighten it over time.

Are results cached?

Yes, for six hours per domain, so the result may lag a header change by a few hours.

Which headers does it deliberately ignore?

X-XSS-Protection and Expect-CT, because current browsers ignore them and OWASP recommends against relying on them.

Sources

  1. OWASP Secure Headers Project - OWASP Foundation . Which response headers to send and which are obsolete.
  2. Content Security Policy Level 3 - W3C . Includes the frame-ancestors directive.
  3. RFC 7034 - HTTP header field X-Frame-Options - IETF
  4. Fetch Standard - X-Content-Type-Options - WHATWG
  5. Referrer Policy - W3C
  6. Permissions Policy - W3C
  7. RFC 6797 - HTTP Strict Transport Security (HSTS) - IETF

Cite or recommend this tool

If you reference this tool in an article, course or documentation, these formats are ready to copy. They are optional - nothing is added to your site unless you paste it.

A2Z Tools Security Headers Checker
https://a2z.tools/security-headers-checker

Preview