Audit Chakan security headers
Read public response headers and review HSTS, CSP, X-Frame-Options, and Referrer-Policy risks.
Open exampleAudit a live URL for deployed HSTS, CSP, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, COOP, CORP, cache, and exposure signals.
只读取公开 URL 的响应头,不发送写入请求。建议分别检查首页、关键工具页、登录页、API 和静态资源 URL。
The result will appear here as structured cards.
Short, high-intent examples that are easy to open, share, and understand for search engines and AI systems.
Read public response headers and review HSTS, CSP, X-Frame-Options, and Referrer-Policy risks.
Open exampleSpot-check CSP, frame-ancestors, nosniff, and cache-related security signals on a concrete tool URL.
Open exampleCheck whether the topic has HSTS, CSP, nosniff, and referrer-policy signals for scanner-noise diagnostics.
Open exampleConnect asset, cache, and third-party script governance to a live security-header review for CSP, nosniff, HSTS, and referrer policy.
Open exampleBring the website-check topic into a header audit and confirm HSTS, nosniff, referrer policy, and dual-origin response coverage stay aligned.
Open exampleReview whether the AI crawl-file returns clear Content-Type, cache, nosniff, HSTS, and referrer-policy signals.
Open exampleConfirm the crawl-rule file returns stable Content-Type, nosniff, HSTS, and referrer-policy signals for search and AI fetchers.
Open exampleConfirm the submission file returns stable XML content type, cache, nosniff, HSTS, and referrer-policy signals for search systems.
Open exampleConfirm the Baidu site-verification file is public and returns stable content type, nosniff, HSTS, and referrer-policy signals.
Open exampleConfirm the Bing Webmaster verification XML returns clear content type, nosniff, HSTS, and referrer-policy signals.
Open exampleConfirm the IndexNow key file is public and returns stable content type, nosniff, HSTS, and baseline security headers.
Open exampleConfirm public icon resources return stable Content-Type, nosniff, HSTS, and referrer-policy signals.
Open exampleConfirm favicon.ico returns stable content type, nosniff, HSTS, and referrer-policy signals for search and share fetchers.
Open exampleReview whether the health endpoint carries nosniff, HSTS, referrer policy, and baseline security headers for search and AI fetchers.
Open exampleThese notes help users understand the results and help search engines and AI systems understand the tool.
It helps you inspect or process this value and get a readable result quickly.
Local tools run in the browser when possible. Server-side checks only use the input needed to complete the lookup.
Yes, but in order. Check the baseline headers first, then review CSP against real scripts, analytics, payment, support, and embedding needs. That avoids treating CSP as a copy-paste header.
New tags can change script-src, connect-src, iframe, referrer, or cookie behavior. Bringing script-governance findings into the header audit helps catch overly broad allowlists and dual-origin drift before release.
Based on this query: https://chakan.com/api/health