Content execution
Content Security Policy limits where scripts, styles and other resources may load from.
HTTP RESPONSE REVIEW
Inspect security headers, redirect behavior and cookie attributes, with practical explanations and carefully scoped recommendations.
SECURITY POSTURE
Content Security Policy limits where scripts, styles and other resources may load from.
Strict Transport Security tells supported browsers to use HTTPS for future connections.
Frame protections help restrict which sites may embed a page and reduce clickjacking exposure.
Secure, HttpOnly and SameSite attributes reduce common routes for cookie exposure and cross-site abuse.
The service retrieves response headers only, discards the response body and redacts every cookie value before returning results.
The score is educational and context-dependent. A missing header is not automatically a vulnerability, and a high score is not a penetration test or certification.