Security check
Check your website’s security headers
Security headers tell the browser how to protect your visitors: always use HTTPS, which scripts may run, whether another site may frame your pages. They cost nothing to send, and most sites send few of them.
Headers the scan checks
Strict-Transport-Security
Whether HSTS is sent, and whether its max-age is at least 180 days.
Content-Security-Policy
Whether a CSP is sent, and whether it allows unsafe-inline or unsafe-eval, which weaken it considerably.
X-Frame-Options
Whether the page can be framed by another site. Not needed when the CSP already sets frame-ancestors.
X-Content-Type-Options, Referrer-Policy, Permissions-Policy
Each stops a specific leak or browser behaviour, and each is a one-line change in the server configuration.
What a finding means
A missing HSTS header and a missing CSP are reported separately because they matter most. The other headers are reported together in one finding, since each is a small server setting. Every finding includes the header value to send.
Where to set them
In the web server (Nginx add_header, Apache Header set or .htaccess), in a CDN or proxy in front of the site, or through a security plugin. On hosted platforms such as Shopify, response headers are managed by the platform.
Questions
- Will a Content-Security-Policy break my site?
- It can if it is too strict. Start with Content-Security-Policy-Report-Only, watch what it would block, then enforce it. A report-only policy alone is reported as missing, because it doesn’t protect anything yet.
- Which page are the headers read from?
- From your site’s main page response. Headers are normally configured for the whole site at once, so that is representative.
- Do headers affect the score?
- Yes. They are part of the security score, which carries 40% of the overall result.
Technical checks, not legal advice. SecurityScan does not replace a consultation with a lawyer.