Security Headers
Audit pasted HTTP response headers for CSP, HSTS, X-Frame-Options, and related controls. No URL is fetched.
Runs in your browser. Nothing is uploaded.
0 characters · 0 lines
0 characters · 0 lines
About this tool
Audit pasted response headers for CSP, HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, and related COOP/CORP headers.
How to use: paste headers from DevTools, read present vs missing. No URL is fetched, so CORS is not involved.
Example: a 200 with only content-type lists the rest as missing. Related: URL parser for the request line.
Related Ops tools
Gitignore Generator
Build a .gitignore from stacked templates for Node, Python, Go, Rust, Java, Next.js, macOS, and Windows. Output is composed locally.
.env Toolkit
Parse KEY=value env files, flag duplicates, and diff two .env blobs. Secrets in env files never leave the browser.
Docker Generator
Generate a Dockerfile or a Compose service snippet from image, ports, and command fields. Snippets are built in the tab.
GitHub Actions Explainer
Explain a GitHub Actions workflow YAML: name, triggers, jobs, and steps. Parsing uses js-yaml in the browser.
cURL Generator
Build a curl command from method, URL, headers, and body. The command is assembled locally so tokens in headers stay in the tab.
Tar Command Generator
Build a tar create or extract command with gz, bz2, or xz flags. A small command helper, not an archiver.