Free tool
Security Headers Checker
Fetches the URL (SSRF-safe) and scores the response headers SiteRune already knows how to read. No login required for this check.
What this check covers
- HTTPS, HSTS, CSP, framing, nosniff, Referrer-Policy, Permissions-Policy, COOP
- Version banners and X-Powered-By
- Mixed content and cookie flags when the HTML is in the response
Read it honestly
- This is not a penetration test.
- Headers are from the final URL after redirects.
Questions
Is this the same as SecurityHeaders.com?
Same idea for the header matrix. SiteRune also walks interiors and robots in the full audit.
Run the complete SiteRune audit
This tool is one chapter. The full brief walks interiors, scores every chapter, and attaches ship files.