Grade any site's HTTP security headers — HSTS, CSP, clickjacking, cookies and more. Same A+–F style as the TLS checker.
X-Frame-Options or CSP frame-ancestorsSecure, HttpOnly and SameSite flagsOnly response headers are fetched — page bodies are discarded. Nothing is stored.