Skip to content
UpgradIQ
How it worksToolsCoursesMembership
Sign inJoin
UpgradIQ

The growth system that knows your business.

A project of UpgradIQ, Inc.

Product

How it worksTools and checksGrowth auditMembership

Learn

CoursesResearchesGuidesUAE founder's guide

Company

AboutAbout AdamContactFAQ
© 2026 UpgradIQ, Inc.Privacy policyTerms and conditionsSecurity
HomeCoursesAccount

We use cookies

Some are needed to run the site and keep you signed in. Others help us understand what’s useful through analytics. We don’t run analytics until you agree. Cookie details

← All the tools

Security headers checker

Reads the headers that decide whether another site can frame your pages, whether script can read your cookies, and whether https is enforced.

This check is part of the membership

Members run it on their own pages, with every other check, the decision tools and the courses.

See the membershipSign in

Why this is worth checking

Headers are the cheapest security a site has, because they are configuration rather than code, and most sites ship without them because nothing breaks when they are missing. HSTS is the one worth setting first: without it, the first request a browser makes to your domain can still be plain http.

What it looks at

  • HSTS, and how long it lasts
  • Whether others can frame your site
  • A Content-Security-Policy at all
  • Sniffing, referrer and permissions

Headers are one layer. A site can carry every one of these and still be insecure in ways no header reaches.

Or have the whole page read for you

The other 12

ReadabilitySubject linePage addressesrobots.txtAI assistantsllms.txtSitemapEmail deliveryHeadingsLink wordingPage essentialsSharing previews