1 item
Scan the current website's public HTTP security headers with HeaderSec. HeaderSec gives developers and site owners a fast view of the HTTP security headers exposed by the current website. Open the extension, confirm the displayed origin, and choose **Scan security headers**. HeaderSec performs a server-side request to that public origin and checks controls including HSTS, Content Security Policy, clickjacking defenses, MIME sniffing protection, referrer policy, permissions policy, cookie attributes, and cross-origin policies. The extension sends only the website origin. It does not send page content, cookies, URL paths, query parameters, fragments, passwords, or form entries. Optional GitHub sign-in connects scans to a HeaderSec account. Anonymous scans remain available.
rating_count is the Chrome Web Store ratings count, not a written-review count.