Skip to main content
Security headers API

Ship security headers like a bank.

Scan any site in seconds - CSP, HSTS, clickjacking, cookie flags and TLS expiry graded A+ to F, with copy-paste fixes for next.config.ts and vercel.json. One lifetime key, no per-credit pricing.

Strict-Transport-Security: max-age=63072000; includeSubDomains; preload

Try it live — no signup

Can't scan it? Paste headers into the Grade Simulator and test a change before you ship it — no fetch, no key.

Everything in one scan call

CSP analysis

Content-Security-Policy parsed and graded — unsafe-inline and unsafe-eval are called out before an XSS finds them.

HSTS & TLS expiry

max-age, includeSubDomains and certificate days-remaining in one call.

Clickjacking shield

X-Frame-Options or CSP frame-ancestors — either keeps your pages out of hostile iframes.

Cookie flags audit

Every Set-Cookie checked for Secure, HttpOnly and SameSite.

Copy-paste fixes

Each failing header ships a ready next.config.ts and vercel.json snippet. Fix in minutes, not sprints.

Monitor API

Wire the REST API into CI or cron and catch regressions the moment a deploy drops a header.

7
Security headers graded per scan
5
Copy-paste fix targets (Nginx → vercel.json)
60s
From URL to graded report
313
Sites scanned

We practice what we preach

This grade is produced live by HeaderShield's own scanner running against HeaderShield's own response headers — 9 of 9 controls passing, including a strict CSP, HSTS preload, clickjacking DENY and a locked-down Permissions-Policy. Scan us yourself above.

Why teams switch to HeaderShield

FeatureFree scannersHeaderShield
API accessNone — manual scans onlyREST API on every paid plan
Fix snippetsGeneric advicenext.config.ts + vercel.json, copy-paste
TLS expiry checkSeparate toolBuilt into every scan
Cookie flags auditNot includedSecure / HttpOnly / SameSite per cookie
CI / cron monitoringNot possibleOne curl in your pipeline

Grade your site in 60 seconds

Create a free key in 30 seconds. 10 scans a month, no card.