Security headers · HTTPS and source evidence

Check security headers and HTTPS redirects

Run a bounded public check for HTTPS delivery, clear-text HTTP redirect behavior, HSTS, Content-Security-Policy, frame protection, nosniff, referrer policy, permissions policy, cross-origin declarations, mixed-content candidates, and unnecessary technology disclosure.

HEAD REQUESTSBOUNDEDREDIRECTS5 MAXTLS SCANNOT CLAIMED

Ready for a public URL.

No sample security score, SSL grade, TLS certificate verdict, vulnerability claim, compliance badge, ranking benefit, or manufactured recommendation appears before a live bounded request.

Security posture supports trust and crawl quality

Use this before deeper vulnerability and performance testing

Start with HTTPS

Search engines, browsers, analytics, and users all expect public pages to settle on HTTPS. Check the clear-text version so old links and typed URLs do not strand visitors on HTTP.

Tighten policy in stages

CSP, HSTS, frame protections, and permissions policies are safest when rolled out with template knowledge and testing. This report shows the declarations that deserve review.

Review page resources

Mixed-content and third-party resource candidates often live in templates, tag managers, embeds, and legacy media. Pair this tool with resource and waterfall checks for execution evidence.