HTTP Security Header Checker

HTTP Security Header Checker

ID: holjjaoiloollfjopcannhihcddmddic

Supported Languages

πŸ‡ΊπŸ‡ΈEnglish

Extension Info & Metadata

Status
Active
Version
1.0.7
Size
0.14 MB
Rating
0.0/5
Reviews
0
Users
2
Type
Extension
Updated
Oct 16, 2025
Category
Developer tools
Price
Free
Featured
No
Visibility
Unlisted
Mature
No
By Google
No
Trusted
No

Publisher Contextual Analysis

Author
KookabearView Profile
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Total Extensions
3
Active
3
Obsolete
0
Listed
1
Unlisted
2
Total Users
3
Screenshot 1

Check if a web page has the recommended HTTP Security Headers based on OWASP guidelines.

Instantly validate your website's HTTP security headers against OWASP recommendations HTTP Security Header Checker is a developer-focused Chrome extension that helps you quickly verify whether a web page includes the recommended HTTP security headers based on the latest OWASP (Open Web Application Security Project) guidelines. Key Features βœ“ Real-time Header Analysis - Click the extension icon to instantly check the current page's security headers βœ“ OWASP Compliance - Validates against industry-standard security header recommendations βœ“ Visual Indicators - Green checkmarks for present headers, red X for missing ones βœ“ Direct Documentation Links - Each header links to the official OWASP documentation βœ“ Technology Detection - Warns when Server headers reveal your technology stack βœ“ Clean, Simple Interface - No configuration needed, works immediately This extension validates the following security headers: β€’ Content-Security-Policy - Prevents XSS, clickjacking, and other code injection attacks β€’ Strict-Transport-Security - Enforces secure HTTPS connections β€’ X-Content-Type-Options - Prevents MIME type sniffing β€’ X-Frame-Options - Protects against clickjacking attacks β€’ X-XSS-Protection - Enables browser's XSS filter β€’ Referrer-Policy - Controls referrer information sent with requests β€’ Permissions-Policy - Controls which browser features can be used Perfect For - Web Developers ensuring their sites follow security best practices - Security Professionals performing quick header audits - DevOps Engineers validating security configurations - QA Testers checking security header implementation - Students learning about web security Educational Tool Each header includes a direct link to the OWASP HTTP Headers Cheat Sheet, making this extension both a validation tool and a learning resource. Click any header's documentation link to understand why it's important and how to implement it correctly. Privacy Focused - No data collection or tracking - Works entirely locally in your browser - Only reads headers from the current tab when you click the extension - Open source and transparent How to Use 1. Navigate to any website 2. Click the HTTP Security Header Checker extension icon 3. View instant results showing which security headers are present or missing 4. Click the documentation links to learn more about each header Built with Modern Standards This extension follows Chrome's Manifest V3 requirements, ensuring compatibility with the latest browser security and performance standards. Open Source This extension is open source and available on GitHub. Contributions and feedback are welcome! Learn More For more information about HTTP security headers and web security best practices, visit the OWASP Secure Headers Project: https://owasp.org/www-project-secure-headers

Item
Type
Severity
Description
webRequest
Permission
Critical
This permission enables the extension to monitor and analyze all web requests made by the browser. Rated Critical because it can observe all network traffic including sensitive data, track browsing behavior, and gather authentication tokens.
activeTab
Permission
Medium
This permission grants temporary access to the current tab. Rated Medium because it can access current page content when invoked, though limited to user-initiated actions.
URLs
12
IPv4
0
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

owasp.org/www-project-secure-headers/https://owasp.org/www-project-secure-headers/#content-security-policy
owasp.org/www-project-secure-headers/https://owasp.org/www-project-secure-headers/#http-strict-transport-security
owasp.org/www-project-secure-headers/https://owasp.org/www-project-secure-headers/#x-content-type-options
owasp.org/www-project-secure-headers/https://owasp.org/www-project-secure-headers/#x-frame-options
owasp.org/www-project-secure-headers/https://owasp.org/www-project-secure-headers/#x-xss-protection
owasp.org/www-project-secure-headers/https://owasp.org/www-project-secure-headers/#referrer-policy
owasp.org/www-project-secure-headers/https://owasp.org/www-project-secure-headers/#permissions-policy
owasp.org/www-project-secure-headers/https://owasp.org/www-project-secure-headers/#server
http:-http://ocsp.digicert.com0X+0οΏ½Lhttp://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
http:-http://ocsp.digicert.com0A+0οΏ½5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0CU
Showing 1 to 10 of 20 rows
Rows per page:

Gain full insight into all external connections.

Upgrade for full visibility.

No IP addresses found
Showing 1 to 3 of 10 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files (scanned top 25 shared text files)

No comparable text files found between these versions.

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.