Security Headers Inspector
4 ratings
)Overview
Instantly check security headers for any website, inspired by securityheaders.com
Security Headers Inspector gives every website you visit an instant letter grade (A+ through F) based on its HTTP security headers, using the weighted scoring of securityheaders.com with one difference: a header only earns points if browsers actually apply its value. 🔒 HOW IT WORKS Every page you visit is automatically graded. The badge shows the letter grade in real time. Click the icon for the full report. All analysis runs locally in your browser. 📊 WHAT YOU GET • Letter grade (A+ to F) with score percentage • Score breakdown: the points each header earned or lost, and why • Quick status pills showing which headers are present or missing • Expandable detail cards for every header with: - Current value or "Not set" - Color-coded verdict (good / warn / bad) - Plain-English explanation of what the header does - Why it matters for security - Recommended value to set • Redirect chain of the page load (for example http → https), including HTTPS upgrades made by the browser • HSTS preload check, with a link to hstspreload.org 🔍 DEEP ANALYSIS • Strict grading: invalid or ignored values earn no points (HSTS with max-age=0 or over plain HTTP, the obsolete X-Frame-Options ALLOW-FROM, Permissions-Policy syntax errors, leaky Referrer-Policy values, and more) • CSP analysis: flags unsafe-inline/unsafe-eval (in script-src and script-src-elem), unsafe-hashes, wildcards, data:, http: and https: sources, missing default-src/object-src/base-uri, Report-Only policies, and correctly handles strict-dynamic/nonce/hash negation. Also suggests frame-ancestors, form-action, upgrade-insecure-requests and Trusted Types • Cookie security: checks every Set-Cookie for Secure, HttpOnly, SameSite, Partitioned, and __Secure-/__Host- prefix rules, and flags cookies browsers reject • Information disclosure detection: flags headers leaking server versions, frameworks, or debug info • Deprecated header detection: identifies headers that are no longer useful (Expect-CT, HPKP, etc.) 🎯 HEADERS EVALUATED FOR GRADING • Content-Security-Policy (25 pts) • Strict-Transport-Security (25 pts) • X-Frame-Options (20 pts, or CSP frame-ancestors) • X-Content-Type-Options (20 pts) • Referrer-Policy (15 pts) • Permissions-Policy (15 pts) Also reports on Cross-Origin-Opener-Policy, Cross-Origin-Resource-Policy, Cross-Origin-Embedder-Policy, X-XSS-Protection, X-Robots-Tag, Alt-Svc, NEL, and Report-To as informational headers. 🛡️ ADDITIONAL FEATURES • Settings page: background re-checks, toolbar badge, and cookie value blurring • Color-coded raw headers: security headers in green, info disclosure in amber, deprecated in purple • Cookie values blurred by default for privacy (click to reveal), and hidden when copying • Copy all raw headers to clipboard with one click • Quick-scan buttons to check on SecurityHeaders.com and SSL Labs • Right-click context menu for external scans • Clear messages for pages that can't be scanned (browser-protected pages) or didn't load (with the browser's error) • Full keyboard and screen reader support • Light and dark theme with persistent preference • Works on Chrome, Brave, Edge, Opera, and other Chromium browsers ⚡ PRIVACY All analysis runs locally in your browser. Nothing is sent to the developer or to any third party, and there's no analytics or tracking. The extension reads the HTTP response headers of the pages you visit. To get complete results it may request the page once more from the same website, without cookies: when you press rescan, when you open the popup on a page it has no data for, or when a page came from the browser cache (which drops some headers). The background re-check can be turned off in the settings, and Incognito tabs are never re-requested. Scan links send only the page address, without its query string. The extension never modifies pages or injects scripts. Built for developers, security engineers, and anyone who cares about web security.
5 out of 54 ratings
Details
- Version2.0.0
- UpdatedSeptember 26, 2026
- Offered byDiogo
- Size59.37KiB
- LanguagesEnglish
- Developer
Email
diogo@carvalhofer.lu - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes
Support
For help with questions, suggestions, or problems, visit the developer's support site