HTTP Security Headers Checker
Scan your website's HTTP security headers and find out how well it's protected against clickjacking, XSS attacks, and protocol downgrade attacks.
What the tool checks
- Strict-Transport-Security (HSTS): enforcing HTTPS
- Content-Security-Policy (CSP): protecting against XSS
- X-Frame-Options: clickjacking protection
- X-Content-Type-Options, Referrer-Policy, and Permissions-Policy
- Overall security score with prioritized recommendations
Why it matters
Security headers protect your visitors and your brand's reputation. Google favors secure websites, and HTTPS is a confirmed ranking signal. Missing headers also make attacks easier, and a compromised or blacklisted site can cause lasting SEO damage.
Detailed guide in the help centerFrequently asked questions
Are security headers an SEO factor?
HTTPS is a confirmed (if lightweight) ranking factor. Other headers don't directly affect rankings, but they protect users and site credibility, which has long-term SEO implications.
What is HSTS?
HTTP Strict Transport Security tells browsers to only connect to your site over HTTPS, even when a user types http://. This prevents protocol downgrade attacks.
What is CSP?
Content-Security-Policy restricts which sources are allowed to load scripts and content on your page, dramatically reducing the risk of cross-site scripting (XSS) attacks.
Rate this tool
Related tools
Want a complete SEO + GEO website analysis?
Run all 20 checks at once, track rankings on Google and Seznam, and get improvement suggestions.
Run full analysis