Επικολλήστε τις κεφαλίδες απάντησης για να βαθμολογήσετε το επίπεδο ασφάλειάς σας
Στα Chrome DevTools: Network → κλικ στο αίτημα → Headers → αντιγράψτε την ενότητα Response Headers.
(Τεκμηρίωση στα αγγλικά)
What it does
Paste a raw block of HTTP response headers and the analyzer grades your security posture A–F, header by header. It checks eight security headers — Strict-Transport-Security (HSTS), Content-Security-Policy (CSP), X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, X-XSS-Protection (deprecated, informational), and Cross-Origin-Opener-Policy (COOP) — each getting a grade: A best practice, B present but weak, C missing or dangerous, F actively harmful. The overall grade is a weighted average (CSP weighs most, the deprecated X-XSS-Protection least), and every non-A row comes with a concrete fix. Header names match case-insensitively, folded multi-line values are joined, and the HTTP/2 200 status line is ignored, so you can paste straight from DevTools. Everything runs 100% client-side.
How to use it
- Open your site in Chrome DevTools: Network → click the request → Headers → copy the Response Headers section.
- Paste it into Response headers (or hit Sample to load a typical mid-grade example).
- Click Analyze. You get an overall grade badge, a 0–100 score, and a per-header checklist.
- Each row shows the header’s current value, a present/missing badge, its grade, and an explanation. Expand Learn more for why the header matters.
- Apply the highlighted Recommendations, re-paste, and re-analyze. Copy exports the full report as text.
Examples
A hardening pass
strict-transport-security: max-age=15768000 grades B — six months is below the one-year best practice; raise it to 31536000 and add includeSubDomains. Once fixed it grades A.
A CSP escape hatch
content-security-policy: default-src 'self'; script-src 'self' 'unsafe-inline' grades B — 'unsafe-inline' re-allows the inline injection CSP exists to stop. A policy carrying both 'unsafe-inline' and 'unsafe-eval' grades F: it looks present but defends nothing. Replace them with nonces or hashes.
Actively harmful values
referrer-policy: unsafe-url (F) leaks full URLs — including query-string tokens — to every site the user visits. strict-transport-security: max-age=0 (F) deletes the HSTS policy outright.
Nothing at all
An empty input is still a valid analysis: every configurable header grades C (overall F, 43/100), and the checklist doubles as a copy-paste setup guide.
Good to know
- Private: parsing and grading are pure local logic — the headers never leave your browser.
- Static, not live: this reads the headers you paste; it does not fetch your site (many sites block cross-origin fetches of their headers anyway). Re-analyze after each server change.
- X-XSS-Protection is the exception: it is deprecated — modern browsers removed the XSS Auditor — so omitting it (or sending
0) is the correct, grade-A state. - Weighted, not averaged equally: CSP carries the most weight, then HSTS; one weak header won’t sink an otherwise strong setup, but the big two dominate.
- Related tools: Basic Auth Generator (credential header), Browser Fingerprint (what sites see without headers), and PII Redactor for the content side of privacy.