Audit CSP, HSTS, X-Frame-Options, and security headers with OWASP grading (A+ to F).
Execution runs 100% locally inside the browser sandbox using HTML5 Canvas, Web Cryptography Subtle API, and Web Workers. No data is ever transmitted across the network.
Zero network latency. Operates completely offline with zero dependencies on third-party backend servers or cloud services.
Built according to official RFC specifications, cryptographic test vectors, and enterprise-grade data transformation standards.
Paste your server's HTTP response headers or raw CSP string.
Inspect your overall security grade (A+ to F), vulnerabilities, and recommendations.
Copy production-ready configuration snippets for Next.js, Nginx, Apache, or Cloudflare.
Content-Security-Policy (CSP), Strict-Transport-Security (HSTS), X-Content-Type-Options, X-Frame-Options, Referrer-Policy, and Permissions-Policy.
Yes, all audits run 100% in client memory without external network calls.
Explore related utilities in the Security & Network suite
Brute-force all 256 single-byte XOR keys with automated English frequency & chi-squared scoring.
Compare memory hardness, GPU ASIC resistance, and security parameters across KDF standards.
Generate secure RFC 6238 Base32 TOTP secret keys and standard otpauth:// URIs for Google Authenticator.
Generate RFC 6844 CAA iodef DNS records to receive unauthorized TLS issuance alerts.