API & MCP

HeaderSec

Scan the current website's public HTTP security headers with HeaderSec.

As of July 2026, HeaderSec has users in the Developer Tools category.

Usersno change0%
Ratingno change0%
— reviews
Reviewsno change0%
Version
0.1.0
Manifest V3

History

1 snapshots

Tracking since Jul 22, 2026.

Not enough history yet for this metric — the chart fills in as we collect more snapshots.
View as table
DateUsersRatingReviewsVersion
Jul 22, 20260.1.0
Now0.1.0

Permissions & access

Permissions
activeTabidentitystorage
Host access
https://api.headersec.com/*

Screenshots

HeaderSec screenshot 1

About

HeaderSec gives developers and site owners a fast view of the HTTP security headers exposed by the current website.

Open the extension, confirm the displayed origin, and choose **Scan security headers**. HeaderSec performs a server-side request to that public origin and checks controls including HSTS, Content Security Policy, clickjacking defenses, MIME sniffing protection, referrer policy, permissions policy, cookie attributes, and cross-origin policies.

The extension sends only the website origin. It does not send page content, cookies, URL paths, query parameters, fragments, passwords, or form entries.

Optional GitHub sign-in connects scans to a HeaderSec account. Anonymous scans remain available.

Technical

Version
0.1.0
Manifest
V3
Size
30.1KiB
Min Chrome
88
Languages
1
Featured
No

Metadata

ID
bdflpckcfgdmfeageoobbiedipphompg
Developer ID
u4d3ee436b66650b844009ba40635a49d
Developer Email
[email protected]
Created
Jul 21, 2026
Last Updated (Store)
Jul 21, 2026
Last Scraped
Jul 22, 2026
Website
headersec.com

Data sourced from the Chrome Web Store · last verified Jul 22, 2026.