Security headers checker

Inspect HTTP response headers the same way a browser would see them on first load. We follow redirects, score common protections, and list every header (except Set-Cookie). This is a read-only public check—no account required.

Only http(s) URLs are accepted. Private networks, localhost, and IPv6 literals are blocked to prevent abuse.