Pemindai Header Keamanan Web
Masukkan URL situs web publik untuk memindai status konfigurasi header keamanan penting: Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, X-Content-Type-Options, dan Permissions-Policy.
Enter a URL to check its HTTP security headers.
Cara kerja
Masukkan data Anda
Isi nilai yang diperlukan, tempel teks Anda, atau unggah file yang ingin diproses.
Lihat hasil seketika
Sebagian besar alat diperbarui secara langsung saat Anda mengetik; beberapa menggunakan satu tombol tindakan.
Gunakan hasil Anda
Salin, unduh, atau bagikan hasil yang dihasilkan — Anda selalu memiliki kendali penuh atas data Anda.
Apa itu Pemindai Header Keamanan Web?
Enter a URL to fetch its HTTP response headers and see which browser-side protections it turns on, and which ones it's missing.
How to scan a site's HTTP security headers
Why this needs a server
Browsers deliberately block a page from reading most of another origin's response headers through JavaScript — that's a core part of the same-origin policy. Checking a site you don't control from the browser alone isn't possible, so this tool's backend makes the request instead and reports back only the headers, never the page's content.
What gets checked
Eight headers that consistently matter for transport security and browser-side hardening: Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, Cross-Origin-Opener-Policy, and Cross-Origin-Resource-Policy. Each has a short explanation next to its result.
This is a starting checklist, not a full audit. A header being present does not confirm its value is well configured for your specific site — a Content-Security-Policy of "default-src *", for instance, counts as present here even though it provides little real protection.
Reading the grade
The score weighs headers by how much they typically matter: Strict-Transport-Security, Content-Security-Policy, and X-Content-Type-Options count for the most, X-Frame-Options, Referrer-Policy, and Permissions-Policy count for less, and the two Cross-Origin-* headers count for least. The grade is a rough summary, not a certification.
What this tool fetches, and what it does not
The URL you enter is sent to a ProntoUso server so it can request the site's public response headers for this scan. The page body is never downloaded, redirects are reported but not followed automatically, and private or internal addresses are refused. The URL and returned headers are not stored.
Pertanyaan yang Sering Diajukan (FAQ)
Can I scan any URL, including internal or local addresses?
No. Requests to private, loopback, link-local, and other internal address ranges are blocked before any connection is made, so this cannot be used to probe your own internal network.
Does it follow redirects?
No. If the URL responds with a redirect, that redirect response's own headers are shown, and the destination is never automatically fetched.
Does a good grade mean the site is fully secure?
No. It means the checked headers are present. Header configuration is one layer of web security among many, and a present header can still be configured too loosely to be effective.
Why does it only work on the default HTTP/HTTPS port?
It keeps the tool focused on scanning real websites rather than becoming a general-purpose port prober.
Alat Terkait
- TersediaLokal
Generator Kata Sandi Kuat & Frasa Sandi (Passphrase)
Buat kata sandi acak yang kuat atau frasa sandi yang mudah diingat dan aman.
- TersediaLokal
Penghasil Hash
Hitung hash MD5, SHA-1, SHA-256, SHA-384, SHA-512, dan CRC32 untuk teks dan file.
- TersediaLokal
Penampil & Penghapus Metadata EXIF Foto
Lihat informasi kamera dan hapus metadata EXIF serta lokasi GPS dari foto Anda.
- TersediaLokal
Generator Header Content Security Policy (CSP)
Susun kebijakan keamanan header CSP untuk melindungi situs web dari serangan XSS.
- TersediaLokal
Pendekode Sertifikat SSL / X.509
Dekode dan periksa informasi sertifikat TLS/SSL PEM, masa berlaku, dan SAN.
- TersediaLokal
Penganalisis Header Email
Analisis header email mentah untuk melacak rute hop, SPF, DKIM, dan DMARC.
- TersediaServer
Pemeriksa Kebocoran Kata Sandi
Periksa apakah kata sandi Anda pernah bocor dalam insiden kebocoran data.
- TersediaLokal
Penghasil HMAC (Hash-based Message Authentication)
Hasilkan tanda tangan HMAC menggunakan kunci rahasia dan algoritma SHA.
- TersediaLokal
Generator & Pemeriksa Kunci SSH (Ed25519 & RSA)
Hasilkan pasangan kunci SSH (Ed25519 / RSA) aman atau periksa fingerprint kunci publik.
- TersediaLokal
Kalkulator Persentase Serbaguna
Hitung persentase dari suatu nilai, persentase kenaikan, penurunan, diskon, dan selisih.