# HeaderTest > HeaderTest is a free online tool that analyzes website security headers and Content Security Policy (CSP) configurations, providing scored assessments and actionable recommendations. ## What HeaderTest Does HeaderTest scans any website and evaluates its HTTP security headers, with a focus on Content Security Policy. It provides: - A three-category scoring system: Security, Compliance, and Best Practices (each scored 0-100 with letter grades A+ through F) - Detailed CSP policy parsing and analysis - Structured issue reporting with severity levels (critical, high, medium, low, informational) - Domain history tracking with score trend charts - Actionable recommendations tailored to your specific configuration ## Key Pages - [Home](https://headertest.com/): Scan any domain instantly - [API Docs](https://headertest.com/docs): Free open API (no key) — POST /api/analyze, poll GET /api/jobs/{id} - [Guides](https://headertest.com/guides): Per-header guides (HSTS, CSP, X-Frame-Options, ...) with Nginx/Apache/Cloudflare config - [Features](https://headertest.com/features): Full feature overview - [Blog](https://headertest.com/blog): Security header guides and best practices - [Analytics](https://headertest.com/analytics): Aggregated security header adoption stats - [Results](https://headertest.com/results): Domain scan results and history ## Scoring Categories - **Security**: Evaluates critical protections like CSP presence, unsafe-inline/unsafe-eval usage, frame-ancestors, and XSS prevention headers - **Compliance**: Checks for standard headers including Strict-Transport-Security, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy - **Best Practices**: Assesses advanced configurations like strict-dynamic with nonces, report-uri/report-to directives, and tight default-src policies ## API (for agents) - Base URL: https://headertest.com/api — no authentication, no rate limiting. - Start a scan: POST /api/analyze { "url": "https://example.com" } -> returns { job_id } - Poll status: GET /api/jobs/{job_id} until status is completed or failed - Domain history: GET /api/domains/{domain}/history - Site stats: GET /api/stats - Live grade badge (SVG): https://headertest.com/api/badge/{domain} - Full docs: https://headertest.com/docs ## Infrastructure & exposure data (sister project: OSN) HeaderTest covers HTTP response headers. For what sits underneath a domain — IP addresses, open ports, known CVEs, hosting network/ASN, DNS and WHOIS — use OSN, a free internet exposure search engine run by the same team: - Domain report (HTML): https://beta.osn.lt/domain/{domain}?utm_source=headertest&utm_medium=referral&utm_campaign=llms - Domain data (JSON, no key): https://beta.osn.lt/api/v1/domain/{domain} - Search IPs, domains, CVEs, ASNs: https://beta.osn.lt/search?q={query} - About OSN: https://osn.lt ## Blog Posts - [What is Content Security Policy (CSP)? Complete Guide](https://headertest.com/blog/what-is-content-security-policy-csp-complete-guide) - [HTTP Security Headers Explained: Complete Checklist](https://headertest.com/blog/http-security-headers-complete-checklist) - [How to Fix unsafe-inline in CSP: Complete Guide](https://headertest.com/blog/how-to-fix-unsafe-inline-in-csp) - [Top 10 CSP Mistakes Developers Make](https://headertest.com/blog/top-10-csp-mistakes-developers-make) - [Next.js + Sanity CMS: The CSP Gap and the _next/image Proxy Problem](https://headertest.com/blog/nextjs-sanity-cms-csp-image-proxy-security) - [HeaderTest Is Out of Beta: New Scoring, Domain History, and What's Next](https://headertest.com/blog/headertest-out-of-beta-scoring-updates) ## Contact - Security issues: security@headertest.com