go-supertools
Security & Privacy Tools

Security Headers & WAF Auditor

Audit security headers, detect WAF, and visualize protection.

Looks up live data What you enter is sent to our server to fetch live results from public sources. Results are cached briefly.

About this tool

Checks a website's response headers for six common security headers and looks for signs of a web application firewall or CDN. Enter a URL (https is assumed if you leave it out) and the tool requests the page, follows redirects and reports whether Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy are present, plus the Server header. WAF detection reports "detected signals" (vendor-specific headers and cookies from Cloudflare, Sucuri, Akamai, Imperva, AWS CloudFront, Fastly, Azure Front Door and F5), which are hints, not proof. This tool uses our server: the URL you enter is sent to our API, which fetches the page for you. Results can be cached for ten minutes. It checks presence only, not whether a header's value is configured well.

How to use it

  1. Enter the site address.
  2. Press Audit.
  3. Check which headers are missing and whether a WAF or CDN was detected.
  4. Add missing headers in your server or CDN settings, then run the audit again.

Common problems

No WAF detected, but the site uses one
Only a few vendors and header signs are checked. A firewall that hides its headers will not show up.
A header shows present but may still be weak
Only the header's existence is checked. For example, a loose CSP counts as present.
Request refused or failed
Private or internal addresses and unusual ports are blocked, and the site may block our server. Only public sites on standard web ports can be audited.