Security headers checker with a fix for every gap
HTTP response headers decide how much a single bug can cost: whether an injected script runs, whether the page can be framed, whether the browser will ever fall back to plain HTTP. RepoVerse reads them from the live site and grades the policy behind them, not just their presence.
The headers it reads
Each header is checked on every page reviewed, so a policy that only exists on the home page is noticed.
- Strict-Transport-Security — present on HTTPS, with a max-age of at least 180 days
- Content-Security-Policy — enforced (not report-only) and restricting scripts
- X-Frame-Options or CSP frame-ancestors — the page cannot be framed by other sites
- X-Content-Type-Options: nosniff — no content-type guessing
- Referrer-Policy — full URLs do not leak to other sites
- Server, X-Powered-By and generator tags — no version numbers advertised
A CSP is graded, not just found
A Content-Security-Policy that allows 'unsafe-inline' scripts, 'unsafe-eval', or script sources such as *, https: or data: looks present and protects little. RepoVerse parses the policy the way a browser does: a nonce or hash cancels 'unsafe-inline', 'strict-dynamic' with a nonce cancels host sources, and a policy without script-src or default-src does not restrict scripts at all. Missing object-src 'none' and base-uri are reported separately.
Copy-paste fixes
Every finding ends with the header to send, for example Strict-Transport-Security: max-age=31536000; includeSubDomains, or a starting policy such as default-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'self'. The current value the site sends is shown next to it, so you can see the difference before you deploy.
What it checks
- ModerateNo HSTS header
Without `Strict-Transport-Security` the browser will still try plain HTTP for typed addresses and old links, which leaves room for an SSL-stripping attack on the first request.
website · CWE-319
- LowHSTS lifetime is short
The browser forgets the HTTPS-only rule quickly, so visitors who come back after the max-age has passed are exposed on their first request again.
website · CWE-319
- ModerateNo Content-Security-Policy
If any page has an injection bug, the injected script runs with nothing to stop it — CSP is the layer that limits what one XSS can do.
website · CWE-693
- LowContent-Security-Policy is only reported, not enforced
A report-only policy logs violations but blocks nothing, so it gives no protection yet.
website · CWE-693
- ModerateCSP allows inline scripts
`'unsafe-inline'` in `script-src` lets injected `<script>` tags and event handlers run, which is the main thing a CSP is there to stop.
website · CWE-79
- LowCSP allows eval
`'unsafe-eval'` lets strings become code through `eval`, `new Function` and string timers, which turns some injection bugs into script execution.
website · CWE-95
- ModerateCSP lets scripts load from anywhere
A `script-src` of `*`, `https:`, `http:` or `data:` allows script from any host, so an attacker who can inject a tag can load their own file and the policy will allow it.
website · CWE-693
- LowCSP leaves plugins or the base URL open
Without `object-src 'none'` old plugin content can still execute; without `base-uri` an injected `<base>` tag can redirect every relative script URL on the page.
website · CWE-693
- ModeratePages can be framed by any site
Another site can load your pages in an invisible frame and trick a logged-in visitor into clicking buttons they cannot see — changing settings, confirming payments.
website · CWE-1021
- LowNo X-Content-Type-Options header
Browsers may guess a response's type from its content, so an uploaded file served as text can end up executed as script or styles.
website · CWE-693
- LowNo Referrer-Policy header
Modern browsers default to a safe policy, but older ones send the full URL — including tokens or IDs in the query string — to every site you link to.
website · CWE-200
- LowServer software and version advertised
A version number in `Server`, `X-Powered-By` or a generator tag tells an attacker exactly which public exploits to try first.
website · CWE-200
Questions
- Which security headers matter most?
- Strict-Transport-Security and a Content-Security-Policy that restricts scripts, followed by frame protection (frame-ancestors or X-Frame-Options) and X-Content-Type-Options: nosniff. Referrer-Policy matters less now that browsers default to a safe policy.
- Is X-Frame-Options still needed if I have a CSP?
- CSP frame-ancestors replaces it in modern browsers. Sending X-Frame-Options: DENY as well costs nothing and covers old browsers. A frame-ancestors directive only works in a header, not in a meta tag.
- Why is my CSP reported even though it exists?
- Because it allows inline scripts, eval or scripts from any host, which are exactly what an injected script needs, or because it is report-only and therefore enforces nothing yet.
Related
- Content Security Policy: writing one that actually protectsWrite a Content-Security-Policy that actually stops XSS: why unsafe-inline, unsafe-eval and wildcard sources defeat it, nonces and strict-dynamic, and a policy to start from.
- HTTPS and HSTS: closing the plain-HTTP gapWhy every site needs HTTPS, a 301 redirect from HTTP and a Strict-Transport-Security header (CWE-319), what max-age to use, and how to avoid mixed content.
- Clickjacking: stolen clicks through an invisible frameHow clickjacking (CWE-1021) hides your page in an invisible frame to steal clicks, and the two headers — CSP frame-ancestors and X-Frame-Options — that prevent it.
- Website security scanner that shows its evidenceFree passive website security scan: HTTPS and HSTS, CSP, cookies, mixed content, exposed keys and outdated JavaScript libraries — with the exact header behind each finding.
Updated 2026-10-11