← The Arsenal
TOOL · LIVE
Header Doctor 🩺
Security headers graded, with copy-paste fixes.
Paste any public URL. We fetch and evaluate HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and more. Missing or weak headers ship with a ready-to-paste nginx/apache/express snippet.