HTTP Response Header Analyzer

Paste a set of HTTP response headers (for example from curl -I or your browser's DevTools) and get a graded report of the recommended security headers: HSTS, CSP, X-Content-Type-Options, clickjacking protection, Referrer-Policy, and Permissions-Policy, each graded Good, Weak or Missing, with a short note saying what it found. It analyses only what you paste.

This is generated in browser and is not sent to pah.moi servers.

About this tool3 paragraphs

A real response can carry a live Set-Cookie session and version banners you may not want to publish, so the analyzer is gated behind a short acknowledgement; past it, a made-up sample is loaded so you can see the grading straight away.

Headers are graded on their value, not on being present. An HSTS max-age under six months is Weak rather than Good; a policy allowing unsafe-inline, unsafe-eval or a wildcard source is Weak, and a CSP opens directive by directive. Every Set-Cookie is audited for Secure, HttpOnly and SameSite, with SameSite=None without Secure and a broken __Host- or __Secure- prefix rule counted as failures rather than as weaknesses. Server, X-Powered-By, Via and their relatives are listed separately as disclosure.

The report can only grade what you pasted, and that is its real limit. Headers that a CDN or proxy adds on the way out will not appear unless you captured the response from outside, and a page of Goods describes one response, not the whole site.

Use it locally This tool has a native command line twin. Build sec-headers-cli from the site's source with:
cargo build --release --bin sec-headers-cli
Source and licence terms