Grade your site security
Enter a URL or paste HTTP response headers to get an A-F grade with detailed findings for CSP, HSTS, X-Frame-Options, and more.
Analyze CSP weaknesses
Get a deep analysis of your Content-Security-Policy — unsafe-inline, unsafe-eval, overly broad sources, and missing directives.
Get a hardened baseline
Copy a production-ready set of security headers with best-practice values for immediate deployment to nginx, Cloudflare, or Vercel.
Check cookie flags
Verify that cookies have Secure, HttpOnly, and SameSite attributes to prevent session hijacking and CSRF.
Detect info disclosure
Flag headers like X-Powered-By and Server that leak technology stack information to potential attackers.
Security Headers Analyzer runs entirely in your browser tab. No data is uploaded, no server processes your input, and no account is required.

Encode and decode Base64 for text, files, images, audio, and video.
Encoding & Data
Format, validate, minify, and explore JSON with tree, table, and map views.
Encoding & Data
Preview and debug Open Graph and Twitter Card social share metadata.
Web & Network
Inspect WHOIS, DNS, SSL, IP geolocation, and certificate transparency.
Web & Network