How to use Security Headers Checker
Enter a public page URL to inspect HSTS, CSP, frame protection, content-type protection, referrer and permissions policies.
What the tool does
Inspect important HTTP security headers and identify missing protection on a public page.
Supported inputs
The public URL, domain or metadata fields shown in the form. Public URL checks can only inspect resources the ToolTapGo server can reach.
Actual output
A diagnostic report that explains observed findings without silently changing the source.
Privacy and processing
Public-site checks may be handled by the ToolTapGo server so the requested public resource can be retrieved.
Limitations
A missing header is a signal to review, not proof that a website is insecure. Correct policies depend on the application.
Common mistakes
Check that the selected input type, units and output format match the task. Do not discard the source before opening the result, and do not treat a preview, estimate or converted file as verified until you have reviewed it.
Frequently asked questions
What can I use Security Headers Checker for?
Inspect important HTTP security headers and identify missing protection on a public page.
What input does Security Headers Checker accept?
The public URL, domain or metadata fields shown in the form. Public URL checks can only inspect resources the ToolTapGo server can reach.
What should I check after using Security Headers Checker?
A missing header is a signal to review, not proof that a website is insecure. Correct policies depend on the application.
Related tasks and guides
- Website SEO Audit — Check page titles, headings, metadata and key on-page SEO signals for a public URL.
- Redirect Checker — Follow HTTP redirects and display each status code and destination.
- Broken Link Checker — Check a limited set of page links and report failed HTTP responses.
- Sitemap Generator — Crawl same-domain pages and create a basic XML sitemap.
