Overview
Scan the current website's public HTTP security headers with HeaderSec.
HeaderSec gives developers and site owners a fast view of the HTTP security headers exposed by the current website. Open the extension, confirm the displayed origin, and choose **Scan security headers**. HeaderSec performs a server-side request to that public origin and checks controls including HSTS, Content Security Policy, clickjacking defenses, MIME sniffing protection, referrer policy, permissions policy, cookie attributes, and cross-origin policies. The extension sends only the website origin. It does not send page content, cookies, URL paths, query parameters, fragments, passwords, or form entries. Optional GitHub sign-in connects scans to a HeaderSec account. Anonymous scans remain available.
0 out of 5No ratings
Details
- Version0.1.0
- UpdatedJuly 21, 2026
- Size30.1KiB
- LanguagesEnglish
- DeveloperWebsite
Email
support@vmcsoft.com - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
HeaderSec has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy.
HeaderSec handles the following:
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes
Support
For help with questions, suggestions, or problems, please open this page on your desktop browser