Security Headers & WAF Auditor
Audit security headers, detect WAF, and visualize protection.
Looks up live data What you enter is sent to our server to fetch live results from public sources. Results are cached briefly.
About this tool
Checks a website's response headers for six common security headers and looks for signs of a web application firewall or CDN. Enter a URL (https is assumed if you leave it out) and the tool requests the page, follows redirects and reports whether Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy are present, plus the Server header. WAF detection reports "detected signals" (vendor-specific headers and cookies from Cloudflare, Sucuri, Akamai, Imperva, AWS CloudFront, Fastly, Azure Front Door and F5), which are hints, not proof. This tool uses our server: the URL you enter is sent to our API, which fetches the page for you. Results can be cached for ten minutes. It checks presence only, not whether a header's value is configured well.
How to use it
- Enter the site address.
- Press Audit.
- Check which headers are missing and whether a WAF or CDN was detected.
- Add missing headers in your server or CDN settings, then run the audit again.
Common problems
- No WAF detected, but the site uses one
- Only a few vendors and header signs are checked. A firewall that hides its headers will not show up.
- A header shows present but may still be weak
- Only the header's existence is checked. For example, a loose CSP counts as present.
- Request refused or failed
- Private or internal addresses and unusual ports are blocked, and the site may block our server. Only public sites on standard web ports can be audited.