FlawPilot
Security use case

Check your website's security headers, for free

Get an instant analysis of HTTP security headers, TLS configuration, DNS records, and cookie security. No account needed, no limits on free scans.

Analysis complete

Site health report

For example.com

0Overall
Critical
1
High
2
Medium
4
Low
3
CriticalAPI key exposed in JS bundle
HighMissing header: Content-Security-Policy
HighMissing header: X-Frame-Options
Headers analyzed
15+
No account needed
Free
Results delivered
<5s

Comprehensive header analysis in one scan

Every scan evaluates 15+ HTTP security headers and grades each one individually. Instead of telling you only whether a header is present, FlawPilot reports how well it's configured, because a misconfigured Content-Security-Policy can be worse than none at all. Configuration quality matters as much as presence.

Header findings

4
Security
Critical

API key exposed in JS bundle

A live OpenAI key was leaked in /static/app.js; rotate immediately.

High

Missing header: Content-Security-Policy

The Content-Security-Policy header is absent from HTTP responses.

Medium

Permissions-Policy not set

Define explicit permissions for camera, microphone, and geolocation.

Pass

Strict-Transport-Security present

HSTS configured with max-age=31536000; includeSubDomains.

Beyond headers: TLS, DNS, and cookies

Security headers are only one layer of your website's defenses. Each scan also evaluates your TLS/SSL certificate and protocol configuration, DNS security records including DNSSEC and CAA, cookie attributes (Secure, HttpOnly, SameSite), and a detailed breakdown of every Content-Security-Policy directive. You get a complete picture from a single run.

Coverage areas

4
Security
Pass

TLS / SSL configuration

Certificate validity, protocol version, and cipher strength evaluated.

Medium

DNS Security: CAA record missing

No CAA record found. Any CA can issue certificates for this domain.

High

Cookie missing flags x3

Cookie '_session_id' is missing HttpOnly and SameSite attributes.

Pass

CSP directive deep-dive

Each directive analyzed for unsafe sources and policy quality.

Actionable recommendations with priority

The scanner doesn't just list problems. Every finding ships with a plain-English explanation of the risk, a severity label, and step-by-step instructions for how to fix it. Recommendations are sorted by impact so you know which changes will lift your score the most, and whether you're on Apache, Nginx, or a CDN, the guidance adapts to your setup.

Recommended fixes

4
Security
High

Add Content-Security-Policy

Define allowed content sources to prevent XSS attacks.

High

Add X-Frame-Options

Add X-Frame-Options to all HTTP responses to block clickjacking.

Medium

Enable HSTS preload

Submit your domain to the HSTS preload list for maximum protection.

Low

Set SameSite on cookies

Add the SameSite attribute to prevent cross-site request forgery.

Frequently asked questions

We evaluate 15+ HTTP security headers including Content-Security-Policy (CSP), Strict-Transport-Security (HSTS), X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, X-XSS-Protection, Cross-Origin-Opener-Policy (COOP), Cross-Origin-Embedder-Policy (COEP), Cross-Origin-Resource-Policy (CORP), Cache-Control, and more. Each header is graded individually based on whether it's present and how well it's configured.

Ready when you are

Check your security headers now

Free, instant results. Enter any URL and see your security score in seconds.

Scan Your Site for Free
Check your website's security headers, for free — FlawPilot