Skip to content Hivex tools · Website Free · No account
Hivex / Tools / HTTP header checker / http://github.com/ Headers of github.com. Every response header a web address sends, with the security headers checked and explained.
What response headers are. Before any page content, a server sends headers: the status, the content type, how long browsers may cache the page, and rules the browser must follow. They are invisible on the page but decide a lot about speed and safety.
The security headers. Strict-Transport-Security (HSTS): browsers use https:// only, even when someone types http://.Content-Security-Policy: where scripts, styles and frames may come from, which stops most injected scripts.X-Content-Type-Options: nosniff: browsers trust the declared file type instead of guessing.X-Frame-Options or CSP frame-ancestors: who may show the page inside a frame, against clickjacking.Referrer-Policy and Permissions-Policy: what the page shares with other sites, and which device features embedded content may ask for.Where to set them. Headers are set by the server, the hosting platform or a CDN in front of it: a config file, a dashboard rule, or the framework's settings. Add them one at a time and check the site after each, starting with nosniff and HSTS, which rarely break anything.
Questions people ask. What are HTTP response headers? Information a server sends before a page: the status, the content type, caching rules, and security rules the browser must follow.
Which security headers should a website send? Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, a framing rule (X-Frame-Options or frame-ancestors), Referrer-Policy and Permissions-Policy.
How do I check the headers of a website? Type the address. The checker follows any redirects and shows every header of the final page, with the security headers checked.
How do I add security headers? In your server, hosting platform or CDN settings. Add them one at a time and test the site after each.
Hivex index
Short names, still free to register.
Starting something new? Hivex keeps a live index of short, brandable .si names nobody has claimed yet, each checked with the registry.
Browse free names From code, or an AI assistant. More Website tools Redirect checker Every hop of a URL, and all four forms of the address. Security headers checker A grade for HSTS, CSP, framing and cookies, with fixes. SSL checker Trust, expiry, the chain and TLS versions of any site. Open Graph checker How a link looks when shared, with the tags checked. Is it down? Down for everyone or just you, and where it fails. robots.txt tester Google, Bing and AI crawlers: allowed or blocked, and why. Sitemap checker Limits, dates and hosts checked, a sample requested live. Who hosts this website Web host, CDN, DNS host, mail provider and registrar. Tech stack checker CMS, framework, hosting and trackers of any site. Domain checker Is a name free to register? Checked live on any extension. All free tools Partners
Domains worth owning.
Checked live · No account needed · Premium sales with AtomPay protection
© 2026 hivex.si. Availability changes all the time, so confirm at the registrar before you pay. Not affiliated with ARNES or register.si. Some domain and product links earn Hivex a commission, at no extra cost to you.
https://github.com/
Checked 08:56:47 UTC · Fetched from Hivex's servers
Status 200 OK
Server github.com
Security headers 5 of 6
Content type text/html Check: No Permissions-Policy. Embedded content may ask for the camera, microphone or location.Note: Followed one redirect to https://github.com/; these are its headers.Good: HSTS is set.Good: Content Security Policy is set.Good: X-Content-Type-Options is set.Good: Referrer-Policy is set.Good: Framing is restricted (X-Frame-Options or frame-ancestors), so other sites cannot embed the page to trick clicks.Response headers of https://github.com/ Header Value accept-ranges bytes cache-control max-age=0, private, must-revalidate connection close content-language
How it got there 01 301 Moved Permanently http://github.com/ → https://github.com/ 20 ms 02 200 OK https://github.com/ 38 ms content-security-policy default-src 'none'; base-uri 'self'; child-src github.githubassets.com github. com/assets-cdn/worker/ github. com/assets/ gist. github. com/assets-cdn/worker/; connect-src 'self' uploads.github.com www.githubstatus.com collector.github.com raw.githubusercontent.com api.github.com github-cloud.s3.amazonaws.com github-production-repository-file-5c1aeb. s3. amazonaws. com github-production-upload-manifest-file-7fdce7. s3. amazonaws. com github-production-user-asset-6210df. s3. amazonaws. com *. rel. tunnels. api. visualstudio. com wss://*. rel. tunnels. api. visualstudio. com github.githubassets.com objects-origin. githubusercontent. com copilot-proxy. githubusercontent. com proxy. individual.
content-type text/html; charset=utf-8
date Sun, 11 Oct 2026 08:56:39 GMT
etag W/"2f96d303dcc58ee195fe942d9a715d62"
referrer-policy origin-when-cross-origin, strict-origin-when-cross-origin
strict-transport-security max-age=31536000; includeSubdomains; preload
vary X-PJAX, X-PJAX-Container, Turbo-Visit, Turbo-Frame, X-Requested-With, X-GitHub-Client-Version, Accept-Language, Sec-Fetch-Site, Accept-Encoding, Accept, X-Requested-With
x-content-type-options nosniff
x-github-request-id CFDD:24B5D3:1571AA6:1BD172D:6ACB4F4F
githubcopilot.
com
proxy.business.githubcopilot.com
proxy. enterprise. githubcopilot. com
*. actions. githubusercontent. com
wss://*. actions. githubusercontent. com
productionresultssa0. blob. core. windows. net
productionresultssa1. blob. core. windows. net
productionresultssa2. blob. core. windows. net
productionresultssa3. blob. core. windows. net
productionresultssa4. blob. core. windows. net
productionresultssa5. blob. core. windows. net
productionresultssa6. blob. core. windows. net
productionresultssa7. blob. core. windows. net
productionresultssa8. blob. core. windows. net
productionresultssa9. blob. core. windows. net
productionresultssa10. blob. core. windows. net
productionresultssa11. blob. core. windows. net
productionresultssa12. blob. core. windows. net
productionresultssa13. blob. core. windows. net
productionresultssa14. blob. core. windows. net
productionresultssa15. blob. core. windows. net
productionresultssa16. blob. core. windows. net
productionresultssa17. blob. core. windows. net
productionresultssa18. blob. core. windows. net
productionresultssa19. blob. core. windows. net
github-production-repository-image-32fea6. s3. amazonaws. com
github-production-release-asset-2e65be. s3. amazonaws. com
insights.github.com
wss://alive. github. com
wss://alive-staging. github. com
api.githubcopilot.com
api.individual.githubcopilot.com
api.business.githubcopilot.com
api.enterprise.githubcopilot.com
wss://production-copilot-host. webpubsub. azure. com
api. github. com/cmc_internal/api/
edge.fullstory.com
rs.fullstory.com;
font-src
github.githubassets.com;
form-action
'self'
github.com
gist.github.com
copilot-workspace.githubnext.com
objects-origin. githubusercontent. com;
frame-ancestors
'none';
frame-src
viewscreen.githubusercontent.com
notebooks.githubusercontent.com
www.youtube-nocookie.com;
img-src
'self'
data:
blob:
github.githubassets.com
media.githubusercontent.com
camo.githubusercontent.com
identicons.github.com
avatars.githubusercontent.com
private-avatars. githubusercontent. com
github-cloud.s3.amazonaws.com
objects.githubusercontent.com
release-assets. githubusercontent. com
secured-user-images. githubusercontent. com
user-images. githubusercontent. com
private-user-images. githubusercontent. com
opengraph.githubassets.com
repository-images. githubusercontent. com
marketplace-screenshots. githubusercontent. com
copilotprodattachments. blob. core. windows. net/github-production-copilot-attachments/
github-production-user-asset-6210df. s3. amazonaws. com
customer-stories-feed.github.com
spotlights-feed.github.com
explore-feed.github.com
*. googleusercontent. com
objects-origin. githubusercontent. com
*. githubusercontent. com
images. ctfassets. net/8aevphvgewt8/;
manifest-src
'self';
media-src
github.com
user-images. githubusercontent. com
secured-user-images. githubusercontent. com
private-user-images. githubusercontent. com
github-production-user-asset-6210df. s3. amazonaws. com
gist.github.com
github.githubassets.com
assets. ctfassets. net/8aevphvgewt8/
videos. ctfassets. net/8aevphvgewt8/;
script-src
github.githubassets.com
'sha256-tSjmyPUky1KbRZ0fw9VUil3wFEbeM82rtbJDygGJAXw=';
style-src
'unsafe-inline'
github.githubassets.com;
upgrade-insecure-requests;
worker-src
github.githubassets.com
github. com/assets-cdn/worker/
github. com/assets/
gist. github. com/assets-cdn/worker/