A restrictive policy can reduce script and content-injection risk but must be tested carefully.
Windows PowerShell
curl.exe -I https://example.commacOS or Linux
curl -I https://example.comWhy paste the headers?
A browser cannot freely read another website’s response headers because of cross-origin security controls. A live URL checker will require a small server-side service when deployed.
0/100
Header posture
Not checked
Suggested priorities
This review covers selected response headers only. A strong result does not prove that the website or application is secure.
Important context
Headers must fit the application.
Tells compatible browsers to use secure connections for a defined period.
Helps prevent untrusted sites from placing pages inside deceptive frames.
