Sitefolio

Free security headers checker

Grade any site's HTTP security headers instantly — HSTS, CSP, X-Frame-Options and more — and see exactly what to add.

http://

Why they matter

Security headers are the browser's instructions for defending your visitors — force HTTPS, block your site from being framed, stop content-type sniffing, restrict what scripts can run. They're invisible, cheap to add, and a common gap on client sites. For agency work, monitoring them means a header dropped during a redeploy becomes an alert, not a vulnerability.

Frequently asked questions

Which headers do you grade?

HSTS, Content-Security-Policy, X-Frame-Options (or CSP frame-ancestors), X-Content-Type-Options, Referrer-Policy and Permissions-Policy — the headers browsers rely on to block common attacks.

Do missing headers mean I'm hacked?

No — but they leave the door open to XSS, clickjacking and MIME attacks. They're easy, high-value wins your host or framework can usually add in minutes.

Is CSP really necessary?

A Content-Security-Policy is the single strongest defence against cross-site scripting. It takes tuning, but even a basic policy meaningfully reduces risk.

Full security posture, monitored.

Sitefolio grades headers, TLS, exposed files and blocklist status on every client site — with alerts.

Get started free