Free security headers checker
Grade any site's HTTP security headers instantly — HSTS, CSP, X-Frame-Options and more — and see exactly what to add.
Why they matter
Security headers are the browser's instructions for defending your visitors — force HTTPS, block your site from being framed, stop content-type sniffing, restrict what scripts can run. They're invisible, cheap to add, and a common gap on client sites. For agency work, monitoring them means a header dropped during a redeploy becomes an alert, not a vulnerability.
Frequently asked questions
Which headers do you grade?
HSTS, Content-Security-Policy, X-Frame-Options (or CSP frame-ancestors), X-Content-Type-Options, Referrer-Policy and Permissions-Policy — the headers browsers rely on to block common attacks.
Do missing headers mean I'm hacked?
No — but they leave the door open to XSS, clickjacking and MIME attacks. They're easy, high-value wins your host or framework can usually add in minutes.
Is CSP really necessary?
A Content-Security-Policy is the single strongest defence against cross-site scripting. It takes tuning, but even a basic policy meaningfully reduces risk.
Sitefolio grades headers, TLS, exposed files and blocklist status on every client site — with alerts.
Get started free