FREE TOOL · NO SIGNUP

Website Security: headers, CSP, cookie hygiene on one page.

We simulate a browser request against your domain and check every security-relevant HTTP header, CSP directive, cookie flag and known vulnerability.

★★★★★ 4.7 / 5 · 76 reviews
15+
Headers checked
CSP
Parser
4s
per domain
TOOL · 09 / 09
Website Security
Headers · CSP · CookiesFREE

By using this tool you agree to our Terms and Privacy Policy

Your data is safe

No storage

Domains are only used for the check and discarded immediately.

Public sources

All checks use publicly accessible data: DNS, SSL certificates, HTTP headers.

No account needed

The tool works completely anonymously and without signup.

GDPR compliant

No personal data, no storage, no sharing.

WEBSITE SECURITY — THE GUIDE

What is HTTP-header website security?

ON THIS PAGE
  1. What is Website Security?
  2. Why do you need this?
  3. Step-by-step in 4 steps
  4. What gets checked?
  5. Glossary
  6. FAQ

What is HTTP-header website security?

Modern browsers evaluate dedicated security headers when loading a page — Content-Security-Policy, HSTS, X-Frame-Options. Missing or weak headers open the door to XSS, clickjacking and mixed content. We check them all in one go.

Why check headers regularly?

A large share of web attacks would be prevented by proper headers:

  • XSS. Without CSP, cross-site scripting is trivial.
  • Clickjacking. Without X-Frame-Options your page can be embedded.
  • MITM. Without HSTS the first HTTP requests are attackable.
  • Cookie theft. Without Secure/HttpOnly, scripts read the cookie.

Step-by-step: Website Security in 4 steps

  1. 1
    Enter a URL
    We send a GET request with a standard browser UA.
  2. 2
    Parse headers
    Every security header is inspected.
  3. 3
    Analyse CSP
    Each directive examined for weaknesses.
  4. 4
    Inspect cookies
    Flags, domain, lifetime.

What gets checked?

We follow the OWASP Secure Headers Project:

Strict-Transport-Security
HSTS value + preload.
Content-Security-Policy
All directives.
X-Frame-Options
Clickjacking protection.
X-Content-Type-Options
MIME-sniffing off.
Referrer-Policy
Which referrers are sent.
Permissions-Policy
Browser-API permissions.
Cookie flags
Secure, HttpOnly, SameSite.
Server disclosure
Version leakage.
GLOSSARY

Web-security vocabulary

CSP
Content Security Policy — defines which sources the browser may load.
HSTS
HTTP Strict Transport Security.
XSS
Cross-Site Scripting.
Clickjacking
Embedded page used for invisible clicks.
CORS
Cross-Origin Resource Sharing.
Mixed content
HTTPS page with HTTP resources.
SameSite
Cookie attribute against CSRF.
Subresource Integrity
Hash validation for external JS.
WHO USES IT

Who checks website security?

Frontend devs
Before production deploy.
Security teams
Quarterly audit.
Compliance
ISO 27001, BSI baseline protection.
Penetration testers
Quick pre-check.
Agencies
Before client launch.
FAQ

FAQ for Website Security

What’s the most important directive?
CSP. Without CSP everything else is cosmetic.
Do I need HSTS preload?
For every production domain — yes.
How is it scored?
OWASP score 0–100. < 50 = insufficient, > 80 = good.
Does it work with SPAs?
Yes, we test the initial GET. Client routing is irrelevant since it’s headerless.
Does it cost?
Web: €0. Monitoring: Mandokit plan.
Do you store URLs?
Only the request ID, no content.

Monitor security headers across every domain.

Mandokit finds, validates and contacts B2B leads for you — as a guided workflow or via API.

Try for free