Security Headers Inspector

Instantly check security headers for any website, inspired by securityheaders.com

As of June 2026, Security Headers Inspector has 87 users and a 5.00/5 rating from 3 reviews in the Privacy & Security category.

Usersno change0%
87
87
Ratingno change0%
5.00
3 reviews
Reviewsno change0%
3
Version
1.6.6
Manifest V3
90-day change · In the last 90 days this extension 3 version updates.

History

9 snapshots

Tracking since Apr 16, 2026.

93.4846.5-0.480000000000004Apr 16, 2026Jun 9, 2026
View as table
DateUsersRatingReviewsVersion
Apr 16, 20261.6.3
Apr 22, 20261.6.3
Apr 26, 202665.0031.6.4
May 4, 2026185.0031.6.5
May 9, 2026175.0031.6.6
May 14, 2026475.0031.6.6
May 21, 2026595.0031.6.6
May 27, 2026605.0031.6.6
Jun 3, 2026625.0031.6.6
Now875.0031.6.6

Changelog

  • May 4, 2026
    description
    Security Headers Inspector gives every website you visit an instant letter grade (A+ through F) based on its HTTP security headers — using the same weighted scoring methodology as securityheaders.com.
    
    🔒 HOW IT WORKS
    Every page you visit is automatically graded. The badge shows the letter grade in real time. Click the icon for the full report — no external requests, everything runs locally in your browser.
    
    📊 WHAT YOU GET
    • Letter grade (A+ to F) with score percentage
    • Quick status pills showing which headers are present or missing
    • Expandable detail cards for every header with:
      - Current value or "Not set"
      - Color-coded verdict (good / warn / bad)
      - Plain-English explanation of what the header does
      - Why it matters for security
      - Recommended value to set
    • Grade impact badges showing how many points each header contributes
    
    🔍 DEEP ANALYSIS
    • CSP analysis — flags wildcards, data: URIs, http: sources, unsafe-inline/unsafe-eval, missing default-src/object-src/base-uri, and correctly handles strict-dynamic/nonce/hash negation
    • Cookie security — checks every Set-Cookie for Secure, HttpOnly, SameSite, and __Secure-/__Host- prefixes
    • Information disclosure detection — flags headers leaking server versions, frameworks, or debug info
    • Deprecated header detection — identifies headers that are no longer useful (Expect-CT, HPKP, etc.)
    
    🎯 HEADERS EVALUATED FOR GRADING
    • Content-Security-Policy (25 pts)
    • Strict-Transport-Security (25 pts)
    • X-Frame-Options (20 pts)
    • X-Content-Type-Options (20 pts)
    • Referrer-Policy (15 pts)
    • Permissions-Policy (15 pts)
    
    Also reports on Cross-Origin-Opener-Policy, Cross-Origin-Resource-Policy, Cross-Origin-Embedder-Policy, X-XSS-Protection, X-Robots-Tag, and Alt-Svc as informational headers.
    
    🛡️ ADDITIONAL FEATURES
    • Color-coded raw headers — security headers in green, info disclosure in amber, deprecated in purple
    • Cookie values blurred by default for privacy (click to reveal)
    • Copy all raw headers to clipboard with one click
    • Quick-scan buttons to check on SecurityHeaders.com and SSL Labs
    • Right-click context menu for external scans
    • Light and dark theme with persistent preference
    • Works on Chrome and Brave
    
    ⚡ PRIVACY
    All analysis runs locally in your browser. No data is sent to any server. The extension only reads HTTP response headers from pages you visit — it does not modify any page content or inject scripts.
    
    Built for developers, security engineers, and anyone who cares about web security.
    Security Headers Inspector gives every website you visit an instant letter grade (A+ through F) based on its HTTP security headers, using the same weighted scoring methodology as securityheaders.com
    
    🔒 HOW IT WORKS
    Every page you visit is automatically graded. The badge shows the letter grade in real time. Click the icon for the full report. No external requests, everything runs locally in your browser.
    
    📊 WHAT YOU GET
    • Letter grade (A+ to F) with score percentage
    • Quick status pills showing which headers are present or missing
    • Expandable detail cards for every header with:
      - Current value or "Not set"
      - Color-coded verdict (good / warn / bad)
      - Plain-English explanation of what the header does
      - Why it matters for security
      - Recommended value to set
    • Grade impact badges showing how many points each header contributes
    
    🔍 DEEP ANALYSIS
    • CSP analysis: flags wildcards, data: URIs, http: sources, unsafe-inline/unsafe-eval, missing default-src/object-src/base-uri, and correctly handles strict-dynamic/nonce/hash negation
    • Cookie security: checks every Set-Cookie for Secure, HttpOnly, SameSite, and __Secure-/__Host- prefixes
    • Information disclosure detection: flags headers leaking server versions, frameworks, or debug info
    • Deprecated header detection: identifies headers that are no longer useful (Expect-CT, HPKP, etc.)
    
    🎯 HEADERS EVALUATED FOR GRADING
    • Content-Security-Policy (25 pts)
    • Strict-Transport-Security (25 pts)
    • X-Frame-Options (20 pts)
    • X-Content-Type-Options (20 pts)
    • Referrer-Policy (15 pts)
    • Permissions-Policy (15 pts)
    
    Also reports on Cross-Origin-Opener-Policy, Cross-Origin-Resource-Policy, Cross-Origin-Embedder-Policy, X-XSS-Protection, X-Robots-Tag, and Alt-Svc as informational headers.
    
    🛡️ ADDITIONAL FEATURES
    • Color-coded raw headers: security headers in green, info disclosure in amber, deprecated in purple
    • Cookie values blurred by default for privacy (click to reveal)
    • Copy all raw headers to clipboard with one click
    • Quick-scan buttons to check on [SecurityHeaders.com](http://SecurityHeaders.com) and SSL Labs
    • Right-click context menu for external scans
    • Light and dark theme with persistent preference
    • Works on Chrome and Brave
    
    ⚡ PRIVACY
    All analysis runs locally in your browser. No data is sent to any server. The extension only reads HTTP response headers from pages you visit. It does not modify any page content or inject scripts.
    
    Built for developers, security engineers, and anyone who cares about web security.
  • May 4, 2026
    short_description
    Instantly check security headers for any website — inspired by securityheaders.com
    Instantly check security headers for any website, inspired by securityheaders.com

Permissions & access

Permissions
alarmswebRequesttabscontextMenusstorage
Host access
<all_urls>

Screenshots

Security Headers Inspector screenshot 1

About

Security Headers Inspector gives every website you visit an instant letter grade (A+ through F) based on its HTTP security headers, using the same weighted scoring methodology as securityheaders.com

🔒 HOW IT WORKS
Every page you visit is automatically graded. The badge shows the letter grade in real time. Click the icon for the full report. No external requests, everything runs locally in your browser.

📊 WHAT YOU GET
• Letter grade (A+ to F) with score percentage
• Quick status pills showing which headers are present or missing
• Expandable detail cards for every header with:
  - Current value or "Not set"
  - Color-coded verdict (good / warn / bad)
  - Plain-English explanation of what the header does
  - Why it matters for security
  - Recommended value to set
• Grade impact badges showing how many points each header contributes

🔍 DEEP ANALYSIS
• CSP analysis: flags wildcards, data: URIs, http: sources, unsafe-inline/unsafe-eval, missing default-src/object-src/base-uri, and correctly handles strict-dynamic/nonce/hash negation
• Cookie security: checks every Set-Cookie for Secure, HttpOnly, SameSite, and __Secure-/__Host- prefixes
• Information disclosure detection: flags headers leaking server versions, frameworks, or debug info
• Deprecated header detection: identifies headers that are no longer useful (Expect-CT, HPKP, etc.)

🎯 HEADERS EVALUATED FOR GRADING
• Content-Security-Policy (25 pts)
• Strict-Transport-Security (25 pts)
• X-Frame-Options (20 pts)
• X-Content-Type-Options (20 pts)
• Referrer-Policy (15 pts)
• Permissions-Policy (15 pts)

Also reports on Cross-Origin-Opener-Policy, Cross-Origin-Resource-Policy, Cross-Origin-Embedder-Policy, X-XSS-Protection, X-Robots-Tag, and Alt-Svc as informational headers.

🛡️ ADDITIONAL FEATURES
• Color-coded raw headers: security headers in green, info disclosure in amber, deprecated in purple
• Cookie values blurred by default for privacy (click to reveal)
• Copy all raw headers to clipboard with one click
• Quick-scan buttons to check on [SecurityHeaders.com](http://SecurityHeaders.com) and SSL Labs
• Right-click context menu for external scans
• Light and dark theme with persistent preference
• Works on Chrome and Brave

⚡ PRIVACY
All analysis runs locally in your browser. No data is sent to any server. The extension only reads HTTP response headers from pages you visit. It does not modify any page content or inject scripts.

Built for developers, security engineers, and anyone who cares about web security.

Technical

Version
1.6.6
Manifest
V3
Size
43.57KiB
Min Chrome
88
Languages
1
Featured
No

Metadata

ID
glhchddldhembfjaicaelbimfbnpfoen
Developer ID
ua568161f6b413179cd4bf091be66129e
Developer Email
[email protected]
Created
Apr 15, 2026
Last Updated (Store)
May 23, 2026
Last Scraped
Jun 9, 2026
Website

Data sourced from the Chrome Web Store · last verified Jun 9, 2026.