Skip to main content

CometWeb tools

Security headers checker

A security headers check for one URL · HSTS, CSP, X-Frame-Options and the rest, each with a status and an explanation

FreeNo account required

Our server fetches the URL, so it reaches our logs. Private and local addresses are rejected, including after a redirect.

This security headers checker fetches a public URL from our server and reads the HTTP response headers that tell a browser how to protect the page: Strict-Transport-Security, Content-Security-Policy, X-Frame-Options or frame-ancestors, X-Content-Type-Options, Referrer-Policy and Permissions-Policy, plus Cross-Origin-Opener-Policy and Cross-Origin-Resource-Policy. Each header gets a status and a short explanation. It also flags Server and X-Powered-By headers that reveal your server software. The result is a signal about browser configuration; finding vulnerabilities in the application itself takes a security test.

Which headers to fix first

Start with HSTS and nosniff. Each is one line in the server or CDN config and rarely breaks anything. HSTS needs the whole site on HTTPS, so start with a shorter max-age, check that every subdomain answers over HTTPS, and only then raise it to a year.

CSP takes the most work and gives the most back. A policy that still allows 'unsafe-inline' scripts stops few XSS attacks. Start with Content-Security-Policy-Report-Only, watch the reports for a week or two, then switch to the enforcing header. You can build the policy in our CSP generator.

Framing and referrer are quick wins. frame-ancestors 'self' (or X-Frame-Options: SAMEORIGIN for older browsers) blocks clickjacking. Referrer-Policy: strict-origin-when-cross-origin keeps paths and query strings, which sometimes hold tokens or email addresses, away from other sites.

Check who sets the headers. A CDN or proxy can add, change or strip a header after your application sends it. We saw this on cometweb.io, where the edge replaced our full CSP with a single directive. This tool shows what reaches a visitor, so if the result differs from your config, look at the layer in between.

Check several kinds of response

Headers usually come from three layers: the application, the web server and the CDN, and rules often cover only some responses. Check the home page, one inner page and an error page, such as a URL that returns 404. The differences show which layer adds a header and which one skips it.

OWASP · Secure Headers Project ↗

Abbreviations in the result

HSTSStrict-Transport-Security
Enforces HTTPS for the time set in max-age.
CSPContent-Security-Policy
The allowed sources of scripts, styles and other resources.
XFOX-Frame-Options
The older way to stop a page being framed.
COOPCross-Origin-Opener-Policy
Isolates the page window from other sites' windows.
CORPCross-Origin-Resource-Policy
Sets who may load a given resource.
This tool patches one problem at a time

TLS, headers, cookies and exposure — with a score breakdown and a remediation plan.