Security Headers Check
Enter a site and see which browser-level protections it sends — and which it is missing — with the fix for each.
Free, no account. Passive checks only — the same requests a browser or DNS lookup makes.
What This Checks
- Strict-Transport-Security (HSTS), including subdomains and preload readiness
- Content-Security-Policy, and whether script-src allows unsafe-inline or unsafe-eval
- Clickjacking, MIME-sniffing and referrer protections
- Cookie flags: Secure, HttpOnly and SameSite
- Whether plain HTTP redirects to HTTPS, and server version disclosure
Why It Matters
Headers are the cheapest security layer there is: one line of configuration each, enforced by every visitor's browser. AI-generated apps routinely ship without them because nobody asked for them in the prompt.
A missing CSP turns an ordinary injection bug into script execution; a missing HSTS header leaves the first visit open to downgrade. Neither shows up in a demo.
Check Every Deploy, Not Just Today
ZipLoom runs this check automatically on every deploy, alongside a dependency vulnerability audit — and can scan your source code on demand or on every commit.
Scan Your App FreeMore Free Checks
Email Security Check For Any Domain · Is Your Source Code Public? Source Map Check · CORS Checker For Your API