Free tool

Check browser security headers on a public website.

Security headers help browsers handle transport security, framing, referrer behavior, and script policy. SiteLeak checks whether common public headers are present and includes the evidence in the report.

SiteLeak report preview showing score and lead-path sections

Customer-path evidence this page checks

Strict-Transport-Security header evidence

Content-Security-Policy header evidence

X-Frame-Options or frame-ancestor protection signals

Referrer-Policy header evidence

Useful for trust maintenance

The report lists missing or weak browser header signals with source URL evidence.

No compliance certification

The checker does not certify security, privacy, or regulatory compliance.

Questions this scan can answer

Does this prove my site is secure?

No. It checks a focused set of public HTTP headers and should be used alongside broader security review.

Can it run without a security tool account?

Yes. The free check uses public HTTP response evidence and does not require credentials.