HTTPHeaderCheck icon

Check headers for OWASP recommendations

The HTTPHeaderCheck tool on binsec.tools is a free online utility designed to assess the HTTP security headers of a website, aligning with OWASP (Open Web Application Security Project) best practices. It evaluates the presence and configuration of various HTTP headers that are crucial for web security.

  • Strict-Transport-Security (HSTS): Enforces secure (HTTPS) connections to the server.
  • X-Frame-Options: Protects against clickjacking by controlling whether the site can be framed.
  • X-Content-Type-Options: Prevents MIME type sniffing.
  • Content-Security-Policy (CSP): Helps detect and mitigate certain types of attacks, including Cross Site Scripting (XSS).
  • X-Permitted-Cross-Domain-Policies: Restricts Adobe Flash and Acrobat from loading data.
  • Referrer-Policy: Governs which referrer information should be included with requests.
  • Cross-Origin Resource Sharing (CORS) Headers: Includes headers like Cross-Origin-Resource-Policy, Cross-Origin-Embedder-Policy, and Cross-Origin-Opener-Policy to manage resource sharing across origins.
  • Cache-Control: Directs caching mechanisms in browsers.
  • Deprecation Awareness: The tool identifies deprecated headers, such as Feature-Policy, Expect-CT, Public-Key-Pins, X-XSS-Protection, and Pragma, advising against their use in modern web applications.

Go to HTTPHeaderCheck
HTTPHeaderCheck icon

Penetration Testing
Tools

On binsec.tools, you’ll find free online tools for penetration testing – the same ones used by the binsec group in real-world pentests. The publicly available tools are primarily designed to gather information and enrich it with additional data. Check them out!

Penetration Testing

Since 2013 we conduct professional penetration test, based on international industry standards and years of experience in penetration testing, red teaming and hacking.

As a company for professional penetration testing, we do some things differently than other pentest provider: As a penetration test firm, we do not sell vulnerability scans as pentest. We do also focus on business security risks. You are looking for a professionally conducted penetration tests? Get the binsec team for your Pentest. Read more about our pentest service.

Contact us

Pentest Knowledge and Tools

binsec.tools logo

Free pentest tools for your security analysis.

Pentest Tools
binsec.wiki logo

Take a look at our wiki page about pentesting.

Pentest WIKI
binsec FAQ logo

Straight answers to common pentesting questions.

Pentest FAQ

Company

binsec GmbH
Solmsstraße 41
60486 Frankfurt am Main
Germany

Legal notice

Director: Patrick Sauer
Authorised Officer: Florian Zavatzki, Dominik Sauer
Registration: Frankfurt am Main, HRB97277
Turnover Tax Identification No.: DE290966808

© 2025 All rights reserved by binsec GmbH.

© 2025 All rights reserved by binsec GmbH.