Loading CheckWebs…
Loading CheckWebs…
A free SecurityHeaders alternative for checking CSP, HSTS, X-Frame-Options, Referrer-Policy, SSL, mixed content, redirects, and privacy/security signals.
Recommended workflow
Check CSP, HSTS, frame protections, content type sniffing, referrer policy, and permissions policy.
Open Security Headers GradeRun SSL, redirect chain, HTTP headers, and mixed-content checks to catch common HTTPS problems.
Open SSL Certificate CheckerUse the CSP generator to draft a practical Content-Security-Policy before testing in report-only mode.
Open CSP Header GeneratorBest fit
Not built for
Included checks
Grade your security headers (CSP, HSTS, X-Frame, etc.)
Check if your website SSL certificate is valid and secure
Find insecure HTTP resources on HTTPS pages
Trace the full redirect chain from URL to final destination
Inspect all HTTP response headers
Audit cookies, tracking scripts, and GDPR compliance signals
Build Content-Security-Policy headers visually
Check if a website supports HTTP/2 or HTTP/3 (QUIC)
Comparison
FAQ
No. CheckWebs checks public browser-facing security signals. It does not replace vulnerability scanning or manual security testing.
Start with HSTS, X-Content-Type-Options, frame protection, and a measured Content-Security-Policy rollout.
Yes. The CSP Generator helps create a starter policy that you can adapt and test on your own infrastructure.
Related alternatives