Check security headers
check_security_headersRead-onlyIdempotent
Read the HTTP security headers a domain's homepage sends, as a browser receives them, and grade each: Strict-Transport-Security, Content-Security-Policy, clickjacking protection (X-Frame-Options or CSP frame-ancestors), X-Content-Type-Options, Referrer-Policy and Permissions-Policy, plus whether http:// redirects to https://, cookie flags, and software version disclosure. Only public web servers on ports 80 and 443 are contacted.
Input Schema
TableJSON Schema
| Name | Required | Description | Default |
|---|---|---|---|
| detail | No | "summary" (default) lists only findings that need action; "full" also lists every passing check. | summary |
| domain | Yes | The domain to check, such as example.com. A website address (https://www.example.com/page) or an email address (jo@example.com) also works; the domain is taken from it. |