Secure Headers Analyzer

Paste an HTTP response and get a graded breakdown of its security headers, cookie flags, and cross-origin policy, checked against OWASP, RFC 6797, CSP Level 3, and RFC 6265bis.

Security & WAF

Analysis runs locally in your browser. Nothing is sent anywhere.

API endpointGEThttps://ronutz.com/api/v1/secure-headersDocumented, not served. Opens the specification.

Kaynaklar

Who uses this