Security Headers

Fetch a URL and grade its HTTP security headers with fix suggestions.

Uses network on request Native desktop macOS & Windows
Security Headers
What it does

Missing or weak security headers are easy to overlook until an audit flags them. The Security Headers tool in HackUtilities requests a URL from your own machine, reads the response headers and grades the security-related ones, with a recommendation for each. Because the request comes from your computer, you can test staging sites and internal hosts that public scanners cannot reach.

Eight headers checked

Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, X-XSS-Protection and Expect-CT.

Status per header

Each header is marked present, missing, warning or info, with its value, a description and a recommended setting.

Value-aware checks

HSTS needs a max-age of at least one year with includeSubDomains, a CSP containing unsafe-inline or unsafe-eval is a warning, and a CSP frame-ancestors directive counts for X-Frame-Options.

Score and grade

Headers are weighted by severity into a percentage score and a grade from A+ to F, with counts of present, missing and warning items.

Full response headers

The analysis includes the complete list of headers the server returned, and the final URL after redirects.

FAQ

What URL formats does it accept?

A full URL, or a bare domain, in which case https:// is added. Redirects are followed, and requests time out after 15 seconds.

Does it scan the site or my code?

No. It makes a single GET request and analyzes only the response headers, not the page content.

Pairs well with
All 46 tools →
Try Security Headers free for 14 days

No card, no account. Every tool included, bought once.

Download