S-SEC

Web Security Header Inspector

Check support and limits

Review this tool’s permission, browser support, and network requirements before running it.

16 checks

Inspect declared HSTS, CSP, CORS, cookie and cross-origin isolation headers.

The public URL or domain is sent to this VM for inspection. Targets and results are not retained; request count, duration and response size are bounded.

Inspection input

Input
Public URL or domain, plus check-specific options when required.
Output
A bounded observation result in JSON.
Scope
The result is a point-in-time observation from this VM, not a guarantee.
Acceptance
Input, time, redirect and response-size limits are enforced.

Ready

Result