Security headers checker, with fixes.
A grade for a site's security headers, every point explained, and the line to add for each one that is missing or weak.
What each header protects.
Strict-Transport-Security: browsers only use HTTPS for the site, so a network attacker cannot downgrade it. A year or more, with includeSubDomains.Content-Security-Policy: where scripts, styles and frames may come from. The strongest single defence against injected scripts, if it avoids 'unsafe-inline'.X-Frame-Optionsorframe-ancestors: stops other sites from framing the page to trick clicks.X-Content-Type-Options: nosniff,Referrer-Policy,Permissions-PolicyandCross-Origin-Opener-Policy: smaller holes closed.
Cookies.
A session cookie should carry Secure (HTTPS only), HttpOnly (out of reach of page scripts) and SameSite (not sent on most cross-site requests). The prefix __Host- pins a cookie to one host. Hivex reads only each cookie's name and flags, never its value.
Adding the headers.
They are set by the web server, the hosting platform or a CDN in front of it. Add one at a time and test, starting with nosniff and HSTS. Build the Content Security Policy in report-only mode first (Content-Security-Policy-Report-Only), watch what it would block, then switch it on.
Questions people ask.
Which security headers should every website send?
Strict-Transport-Security, a Content-Security-Policy, X-Content-Type-Options: nosniff, a framing rule (X-Frame-Options or frame-ancestors) and a Referrer-Policy; Permissions-Policy and Cross-Origin-Opener-Policy add more.
How is the grade worked out?
Each check earns points (HSTS and the Content Security Policy count most), headers that reveal the software cost a few, and the total maps to a letter. It is Hivex's own weighting of OWASP's recommendations; every point is shown.
What is HSTS preload?
A list built into browsers of sites that are only ever opened over HTTPS, even on the first visit. A site joins at hstspreload.org once its HSTS header has max-age of a year or more, includeSubDomains and preload.
Why is 'unsafe-inline' a problem in a Content Security Policy?
It lets any inline script run, so an attacker who injects a script tag gets it executed and the policy stops almost nothing. Use nonces or hashes for the inline scripts you need.
Should I still send X-XSS-Protection?
No. Current browsers removed the filter it controlled. Set it to 0 or leave it out, and rely on a Content Security Policy.
Hivex index
Short names, still free to register.
Starting something new? Hivex keeps a live index of short, brandable .si names nobody has claimed yet, each checked with the registry.
From code, or an AI assistant.
Hivex's free JSON API and MCP server check domains, DNS and registration records from your own code or from AI assistants that speak MCP. No key needed.
More Website tools
- Redirect checkerEvery hop of a URL: status code, target and time.
- HTTP header checkerAll response headers, with the security headers checked.
- SSL checkerTrust, expiry, the chain and TLS versions of any site.
- Open Graph checkerHow a link looks when shared, with the tags checked.
- Is it down?Down for everyone or just you, and where it fails.
- robots.txt testerGoogle, Bing and AI crawlers: allowed or blocked, and why.
- Sitemap checkerLimits, dates and hosts checked, a sample requested live.
- Who hosts this websiteWeb host, CDN, DNS host, mail provider and registrar.
- Tech stack checkerCMS, framework, hosting and trackers of any site.
- Domain checkerIs a name free to register? Checked live on any extension.
Sources
- OWASP Secure Headers Project: recommended headers (updated 4 October 2026)
- MDN: Content-Security-Policy
- hstspreload.org: the HSTS preload list and its requirements
- RFC 6797: HTTP Strict Transport Security
- RFC 6265: HTTP state management (cookies)
By Hivex. Updated 10 October 2026. Addresses are fetched live from Hivex's servers; page contents are never read or stored.