Audit a site's HTTP security headers — HSTS, CSP, X-Frame-Options, CORS and cookie flags — get a grade and a ready-to-paste Caddy fix. Leave blank to see your own request headers.
Run the tool above. Results are shown as clear cards — raw JSON is available too.
Check next
Learn more