| | | | | |
---|
View Security Headers |
|
From March 18, 2025 -
redirect safe conditionally -
defense-in-depth with "always" option -
analyze server headers -
issues on GitHub -
janwillemstegink.nl |
Category | Header | IPv4 and no www | IPv6 and no www | IPv4 with www | IPv6 with www |
Client URL | http:// curl error | | | | |
General | http:// HTTP code | | | | |
General | http:// rewrite redirected URL | | | | |
General | http:// effective URL | | | | |
General | http:// HTTP protocol | | | | |
General | http:// server | | | | |
|
|
|
|
|
|
Client URL | https:// curl error | | | | |
General | https:// HTTP code | | | | |
General | https:// effective URL | | | | |
General | https:// HTTP protocol | | | | |
General | https:// server | | | | |
General | date | | | | |
General | content type | | | | |
Server Disclosure Headers | X-Powered-By - header | | | | |
Server Disclosure Headers | X-Powered-By - body | | | | |
Strict Transport & Connection Security | HTTP Public-Key-Pinning (HPKP) - obsolete | | | | |
Strict Transport & Connection Security | HTTP Strict-Transport-Security (HSTS) | | | | |
Content Restrictions & Injection Protection | Content-Security-Policy (CSP) | | | | |
Content Restrictions & Injection Protection | X-Content-Type-Options | | | | |
Content Restrictions & Injection Protection | X-XSS-Protection | | | | |
Cross-Origin & Embedding Security | X-Frame-Options | | | | |
Cross-Origin & Embedding Security | Cross-Origin-Embedder-Policy (COEP) | | | | |
Cross-Origin & Embedding Security | Cross-Origin-Opener-Policy (COOP) | | | | |
Cross-Origin & Embedding Security | Cross-Origin-Resource-Policy (CORP) | | | | |
Cross-Origin & Embedding Security | Cross-Origin-Embedder-Policy-Report-Only | | | | |
Cross-Origin & Embedding Security | Cross-Origin-Opener-Policy-Report-Only | | | | |
Cross-Origin & Embedding Security | Cross-Origin-Resource-Policy-Report-Only | | | | |
Feature & Permissions Control | Feature-Policy - not for use anymore | | | | |
Feature & Permissions Control | Permissions-Policy | | | | |
Referrer & Privacy Control | Referrer-Policy | | | | |
Certificate & Caching Security | Expect-CT (Certificate Transparency) - old | | | | |
Certificate & Caching Security | Cache-Control | | | | |
Certificate & Caching Security | Pragma | | | | |