HeaderLint

HTTP security header scanner with A-F grading

As of June 2026, HeaderLint has users in the Developer Tools category.

Usersno change0%
Ratingno change0%
— reviews
Reviewsno change0%
Version
0.5.1
Manifest V3

History

3 snapshots

Tracking since Apr 1, 2026.

Not enough history yet for this metric — the chart fills in as we collect more snapshots.
View as table
DateUsersRatingReviewsVersion
Apr 1, 20260.5.1
Apr 17, 20260.5.1
Apr 27, 20260.5.1
Now0.5.1

Permissions & access

Permissions
webRequeststorage
Host access
<all_urls>

Screenshots

HeaderLint screenshot 1

About

HeaderLint analyzes HTTP security headers on the current browser tab and provides an A-F letter grade with per-header findings and copy-paste remediation guidance.

Because it runs inside your existing browser session, HeaderLint can scan pages behind login — no credentials or proxy setup required.

Headers analyzed:
  - Content-Security-Policy (CSP)
  - Strict-Transport-Security (HSTS)
  - Referrer-Policy
  - X-Content-Type-Options
  - Permissions-Policy
  - X-Frame-Options
  - X-XSS-Protection

Each header is scored as Correct (100), Weak (50), or Missing (0). The overall score is a weighted sum across all seven headers, mapped to a letter grade (A through F).

For every finding, HeaderLint shows:
  - A severity badge (Pass / Weak / Missing)
  - A plain-language explanation of the issue
  - A recommended header value you can copy directly into your server config
  - A link to MDN documentation

Click "Copy JSON" to export the full analysis as structured JSON for reporting or automation.

Supports light and dark mode based on your system preference.

Technical

Version
0.5.1
Manifest
V3
Size
64.39KiB
Min Chrome
88
Languages
1
Featured
No

Metadata

ID
ljdlfmmjplmbgknpialhldkpbkegpfcg
Developer ID
uf363257c706bae32cfb684f3db6d21b6
Developer Email
[email protected]
Created
Mar 26, 2026
Last Updated (Store)
Mar 27, 2026
Last Scraped
Jun 10, 2026
Website
Support URL

Data sourced from the Chrome Web Store · last verified Jun 10, 2026.