LW IT Solutions

HTTP Security Header Checker

Security headers are easy to set and easy to set uselessly. A Content-Security-Policy that permits unsafe-inline is present and does nothing against the attack it exists for. This reads what an address actually sends back and judges the effect, not the presence.

The address is fetched once from this server, with a plain GET and no cookies. Requests to private networks, to loopback and to link-local addresses are refused, including through redirects. The query is protected by reCAPTCHA v3; the calling IP address and the target are stored for one hour to limit the rate.

OTHER TOOLS