Analyze your HTTP security headers including CSP, HSTS and X-Frame-Options. Get an A-F grade and actionable recommendations.
What is an HTTP security headers check?
An HTTP security headers check fetches a public URL and evaluates whether browser-enforced response headers are present and correctly configured. Strong headers reduce XSS, clickjacking, MIME sniffing, and insecure transport risks. Vigilbase grades the result A through F and explains what to fix.
Agents can run the same non-intrusive scan via POST /api/v1/agent/tools/security-headers/execute.
Security headers checker FAQ
What does the Vigilbase HTTP Security Headers Checker do?
It fetches a public URL, inspects response headers against the OWASP Secure Headers Project expectations, and returns an A-F grade with per-header findings and remediation guidance.The result describes the responses available at scan time. A header grade does not test authenticated application behavior or prove that the site is free of vulnerabilities.A practical website protection guideWebsite Security Check
Which headers are checked?
The scan covers Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, and Cross-Origin isolation headers such as COOP, COEP, and CORP.Headers should fit the application and browser features it uses. Validate proposed CSP, framing and cross-origin policies with representative user journeys before enforcing them.A practical website protection guideManaged WAF operations and change control
Can agents run this scan autonomously?
Yes. Agents can POST {"target":"https://example.com"} to https://vigilbase.com/api/v1/agent/tools/security-headers/execute without Turnstile (optional developer API key from https://one.vigilbase.com/developers). See https://vigilbase.com/developers. The browser UI remains available for interactive use.Use the documented API contract and respect rate limits. This endpoint analyzes public headers; it does not authorize intrusive testing or change the target configuration.Run a check through the public APIAPI authentication and rate limits
Is the Security Headers Checker free?
Yes. The public tool and agent API are free for non-intrusive header analysis. No Vigilbase account is required.The initial header analysis does not require a Vigilbase account. Optional reports and other tools can have separate email or authorization requirements.Compare the public security checksTool access and verification requirements