Security headers audit

Audit a live URL for deployed HSTS, CSP, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, COOP, CORP, cache, and exposure signals.

InputEnter a value to inspect

只读取公开 URL 的响应头,不发送写入请求。建议分别检查首页、关键工具页、登录页、API 和静态资源 URL。

Waiting

The result will appear here as structured cards.

Example results you can open

Short, high-intent examples that are easy to open, share, and understand for search engines and AI systems.

Header audit

Audit Chakan security headers

Read public response headers and review HSTS, CSP, X-Frame-Options, and Referrer-Policy risks.

Open example
Tool page security

Audit security headers on a tool page

Spot-check CSP, frame-ancestors, nosniff, and cache-related security signals on a concrete tool URL.

Open example
Log topic security

Audit security headers on the scanner-noise log topic

Check whether the topic has HSTS, CSP, nosniff, and referrer-policy signals for scanner-noise diagnostics.

Open example
Resource headers

Audit resource-topic security headers

Connect asset, cache, and third-party script governance to a live security-header review for CSP, nosniff, HSTS, and referrer policy.

Open example
Website-check headers

Audit website-check topic security headers

Bring the website-check topic into a header audit and confirm HSTS, nosniff, referrer policy, and dual-origin response coverage stay aligned.

Open example
llms headers

Audit llms.txt security headers

Review whether the AI crawl-file returns clear Content-Type, cache, nosniff, HSTS, and referrer-policy signals.

Open example
robots headers

Audit robots.txt security headers

Confirm the crawl-rule file returns stable Content-Type, nosniff, HSTS, and referrer-policy signals for search and AI fetchers.

Open example
sitemap headers

Audit sitemap.xml security headers

Confirm the submission file returns stable XML content type, cache, nosniff, HSTS, and referrer-policy signals for search systems.

Open example
Baidu headers

Audit Baidu verification file security headers

Confirm the Baidu site-verification file is public and returns stable content type, nosniff, HSTS, and referrer-policy signals.

Open example
Bing headers

Audit BingSiteAuth.xml security headers

Confirm the Bing Webmaster verification XML returns clear content type, nosniff, HSTS, and referrer-policy signals.

Open example
IndexNow headers

Audit IndexNow key file security headers

Confirm the IndexNow key file is public and returns stable content type, nosniff, HSTS, and baseline security headers.

Open example
Icon headers

Audit brand icon security headers

Confirm public icon resources return stable Content-Type, nosniff, HSTS, and referrer-policy signals.

Open example
Favicon headers

Audit favicon.ico security headers

Confirm favicon.ico returns stable content type, nosniff, HSTS, and referrer-policy signals for search and share fetchers.

Open example
Health headers

Check health JSON security headers

Review whether the health endpoint carries nosniff, HSTS, referrer policy, and baseline security headers for search and AI fetchers.

Open example

FAQ

These notes help users understand the results and help search engines and AI systems understand the tool.

What does Security headers audit do?

It helps you inspect or process this value and get a readable result quickly.

Is my input saved?

Local tools run in the browser when possible. Server-side checks only use the input needed to complete the lookup.

Should I audit security headers and CSP together?

Yes, but in order. Check the baseline headers first, then review CSP against real scripts, analytics, payment, support, and embedding needs. That avoids treating CSP as a copy-paste header.

Why recheck security headers after adding third-party scripts?

New tags can change script-src, connect-src, iframe, referrer, or cookie behavior. Bringing script-governance findings into the header audit helps catch overly broad allowlists and dual-origin drift before release.

Related long-tail searches

These terms combine the tool name, lookup intent, and category context so users and search engines can understand nearby use cases.

security headers auditHSTS CSP checkerReferrer Policy checkerPermissions Policy checkerX-Frame-Options checkersite security header scorescanner traffic security header auditChina server security headers