ToolsSecure development
Security headers check.
Paste your response headers. Get a straight read on what is missing.
Runs in your browser. Nothing you enter is sent, stored or logged.
Runs entirely in your browser; this page makes no request to your site. Accepts raw headers or curl output.
Header reading
Paste headers to get a read.
Headers are one layer of a defensible application, and the easiest one to check. The application behind them is where a penetration test earns its fee.
What this does, and what it deliberately does not.
This check parses headers you paste; it never calls your site. Headers are one layer. A web application penetration test exercises the application behind them, which is where most real findings live.
Headers pass but you have never been tested?
Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.