Security Headers
Fetch a URL and grade its HTTP security headers with fix suggestions.
Missing or weak security headers are easy to overlook until an audit flags them. The Security Headers tool in HackUtilities requests a URL from your own machine, reads the response headers and grades the security-related ones, with a recommendation for each. Because the request comes from your computer, you can test staging sites and internal hosts that public scanners cannot reach.
Eight headers checked
Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, X-XSS-Protection and Expect-CT.
Status per header
Each header is marked present, missing, warning or info, with its value, a description and a recommended setting.
Value-aware checks
HSTS needs a max-age of at least one year with includeSubDomains, a CSP containing unsafe-inline or unsafe-eval is a warning, and a CSP frame-ancestors directive counts for X-Frame-Options.
Score and grade
Headers are weighted by severity into a percentage score and a grade from A+ to F, with counts of present, missing and warning items.
Full response headers
The analysis includes the complete list of headers the server returned, and the final URL after redirects.
What URL formats does it accept?
A full URL, or a bare domain, in which case https:// is added. Redirects are followed, and requests time out after 15 seconds.
Does it scan the site or my code?
No. It makes a single GET request and analyzes only the response headers, not the page content.
Parse PEM certificates and inspect the TLS certificate chain of a host.
Open →Send HTTP requests and inspect status, headers, body and timing.
Open →Query DNS records with any resolver and run WHOIS lookups.
Open →No card, no account. Every tool included, bought once.