+961 70 327 329 info@nemeritsolutions.com Mon - Fri, 9:00 - 18:00
5.0 customer rating

Free tool

HTTP Security Headers Checker

Grade a website on the security headers browsers rely on, including HSTS, Content Security Policy, X Frame Options and Referrer Policy, with the exact rules to add.

What these headers actually do

Security headers are instructions your server sends with every page, telling the browser what it is and is not allowed to do with your site. They cost nothing, they are configuration rather than code, and they close off entire categories of attack before any code is involved. A site can be perfectly written and still be exploited through a browser behaviour that a single header would have switched off.

The two that carry most of the weight are Strict-Transport-Security and Content-Security-Policy. The first makes the encrypted connection compulsory rather than optional, which closes the window where somebody on the same network can intercept the first unencrypted request. The second lists the places your page may load code from, so a script injected through a comment box or a vulnerable plugin never executes, because it did not come from an approved source.

Content Security Policy is the one to be careful with

It is also the only header on this list that can break a working site. If the policy does not mention a source your pages genuinely use, such as an analytics script, a font service or an embedded map, the browser will block it and that part of the page will stop working. The sensible approach is to deploy it in report only mode first, watch what gets flagged for a week, then enforce it once the list is complete.

If a policy on a live site allows unsafe-inline, that is usually a sign somebody added the header to pass a scan rather than to protect anything, since inline scripts are exactly what the policy exists to stop.

A grade is not a security audit

A site can score an A here and still be wide open. These headers say nothing about weak passwords, an out of date plugin, SQL injection in a form, a database reachable from the internet or an administration panel with no second factor. What they do give you is a quick and honest reading of whether anyone has paid attention to the basics, and in our experience that answer correlates closely with what the rest of the setup looks like.

Get in touch

Streamline your technology with IT support you can reach

Tell us what is slowing you down. We will come back with a plan and a price no obligation.