S-SEC
16 checksWeb Security Header Inspector
Check support and limits
Review this tool’s permission, browser support, and network requirements before running it.
Inspect declared HSTS, CSP, CORS, cookie and cross-origin isolation headers.
The public URL or domain is sent to this VM for inspection. Targets and results are not retained; request count, duration and response size are bounded.