Security

HTTP-Header

Response-Header anzeigen und Security-Policies prüfen.

URL http or https (default https). Up to 3 redirects are followed.
https://github.com/
Status: 200 HTTP/1.1 96 ms
B
Security grade?
Score
82 / 100
Status
200
Protocol?
HTTP/1.1
Latency?
96 ms
Security audit
  • pass Strict-Transport-Security? +25/25
    HSTS is set with a long max-age — browsers will refuse plaintext HTTP for the next 6+ months.
    max-age=31536000; includeSubdomains; preload
  • pass Content-Security-Policy? +25/25
    CSP is set with reasonable defaults — script and style sources are restricted.
    default-src 'none'; base-uri 'self'; child-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/; connect-src 'self' uploads.github.com www.githubstatus.com collector.github.com raw.githubusercontent.com api.github.com github-cloud.s3.amazonaws.com github-production-repository-file-5c1aeb.s3.amazonaws.com github-production-upload-manifest-file-7fdce7.s3.amazonaws.com github-production-user-asset-6210df.s3.amazonaws.com *.rel.tunnels.api.visualstudio.com wss://*.rel.tunnels.api.visualstudio.com github.githubassets.com objects-origin.githubusercontent.com copilot-proxy.githubusercontent.com proxy.individual.githubcopilot.com proxy.business.githubcopilot.com proxy.enterprise.githubcopilot.com *.actions.githubusercontent.com wss://*.actions.githubusercontent.com productionresultssa0.blob.core.windows.net productionresultssa1.blob.core.windows.net productionresultssa2.blob.core.windows.net productionresultssa3.blob.core.windows.net productionresultssa4.blob.core.windows.net productionresultssa5.blob.core.windows.net productionresultssa6.blob.core.windows.net productionresultssa7.blob.core.windows.net productionresultssa8.blob.core.windows.net productionresultssa9.blob.core.windows.net productionresultssa10.blob.core.windows.net productionresultssa11.blob.core.windows.net productionresultssa12.blob.core.windows.net productionresultssa13.blob.core.windows.net productionresultssa14.blob.core.windows.net productionresultssa15.blob.core.windows.net productionresultssa16.blob.core.windows.net productionresultssa17.blob.core.windows.net productionresultssa18.blob.core.windows.net productionresultssa19.blob.core.windows.net github-production-repository-image-32fea6.s3.amazonaws.com github-production-release-asset-2e65be.s3.amazonaws.com insights.github.com wss://alive.github.com wss://alive-staging.github.com api.githubcopilot.com api.individual.githubcopilot.com api.business.githubcopilot.com api.enterprise.githubcopilot.com wss://production-copilot-host.webpubsub.azure.com edge.fullstory.com rs.fullstory.com; font-src github.githubassets.com; form-action 'self' github.com gist.github.com copilot-workspace.githubnext.com objects-origin.githubusercontent.com; frame-ancestors 'none'; frame-src viewscreen.githubusercontent.com notebooks.githubusercontent.com www.youtube-nocookie.com; img-src 'self' data: blob: github.githubassets.com media.githubusercontent.com camo.githubusercontent.com identicons.github.com avatars.githubusercontent.com private-avatars.githubusercontent.com github-cloud.s3.amazonaws.com objects.githubusercontent.com release-assets.githubusercontent.com secured-user-images.githubusercontent.com user-images.githubusercontent.com private-user-images.githubusercontent.com opengraph.githubassets.com marketplace-screenshots.githubusercontent.com copilotprodattachments.blob.core.windows.net/github-production-copilot-attachments/ github-production-user-asset-6210df.s3.amazonaws.com customer-stories-feed.github.com spotlights-feed.github.com explore-feed.github.com objects-origin.githubusercontent.com *.githubusercontent.com images.ctfassets.net/8aevphvgewt8/; manifest-src 'self'; media-src github.com user-images.githubusercontent.com secured-user-images.githubusercontent.com private-user-images.githubusercontent.com github-production-user-asset-6210df.s3.amazonaws.com gist.github.com github.githubassets.com assets.ctfassets.net/8aevphvgewt8/ videos.ctfassets.net/8aevphvgewt8/; script-src github.githubassets.com; style-src 'unsafe-inline' github.githubassets.com; upgrade-insecure-requests; worker-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/
  • pass X-Frame-Options / frame-ancestors? +15/15
    Clickjacking is blocked — page cannot be embedded in third-party iframes.
    deny
  • pass X-Content-Type-Options +10/10
    nosniff is set — browsers will not MIME-sniff non-script responses as JavaScript.
    nosniff
  • warn Referrer-Policy? +7/15
    Referrer policy leaks parts of the URL cross-origin — switch to strict-origin-when-cross-origin.
    origin-when-cross-origin, strict-origin-when-cross-origin
  • fail Permissions-Policy? +0/10
    No Permissions-Policy — third-party iframes can request sensitive features without restriction.
Response headers
date: Sun, 26 Jul 2026 18:12:49 GMT content-type: text/html; charset=utf-8 vary: X-PJAX, X-PJAX-Container, Turbo-Visit, Turbo-Frame, X-Requested-With, X-GitHub-Client-Version, Accept-Language, Sec-Fetch-Site,Accept-Encoding, Accept, X-Requested-With content-language: en-US etag: W/"3f956f090971482e9a8d1fe36c4b9d2c" cache-control: max-age=0, private, must-revalidate strict-transport-security: max-age=31536000; includeSubdomains; preload x-frame-options: deny x-content-type-options: nosniff x-xss-protection: 0 referrer-policy: origin-when-cross-origin, strict-origin-when-cross-origin content-security-policy: default-src 'none'; base-uri 'self'; child-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/; connect-src 'self' uploads.github.com www.githubstatus.com collector.github.com raw.githubusercontent.com api.github.com github-cloud.s3.amazonaws.com github-production-repository-file-5c1aeb.s3.amazonaws.com github-production-upload-manifest-file-7fdce7.s3.amazonaws.com github-production-user-asset-6210df.s3.amazonaws.com *.rel.tunnels.api.visualstudio.com wss://*.rel.tunnels.api.visualstudio.com github.githubassets.com objects-origin.githubusercontent.com copilot-proxy.githubusercontent.com proxy.individual.githubcopilot.com proxy.business.githubcopilot.com proxy.enterprise.githubcopilot.com *.actions.githubusercontent.com wss://*.actions.githubusercontent.com productionresultssa0.blob.core.windows.net productionresultssa1.blob.core.windows.net productionresultssa2.blob.core.windows.net productionresultssa3.blob.core.windows.net productionresultssa4.blob.core.windows.net productionresultssa5.blob.core.windows.net productionresultssa6.blob.core.windows.net productionresultssa7.blob.core.windows.net productionresultssa8.blob.core.windows.net productionresultssa9.blob.core.windows.net productionresultssa10.blob.core.windows.net productionresultssa11.blob.core.windows.net productionresultssa12.blob.core.windows.net productionresultssa13.blob.core.windows.net productionresultssa14.blob.core.windows.net productionresultssa15.blob.core.windows.net productionresultssa16.blob.core.windows.net productionresultssa17.blob.core.windows.net productionresultssa18.blob.core.windows.net productionresultssa19.blob.core.windows.net github-production-repository-image-32fea6.s3.amazonaws.com github-production-release-asset-2e65be.s3.amazonaws.com insights.github.com wss://alive.github.com wss://alive-staging.github.com api.githubcopilot.com api.individual.githubcopilot.com api.business.githubcopilot.com api.enterprise.githubcopilot.com wss://production-copilot-host.webpubsub.azure.com edge.fullstory.com rs.fullstory.com; font-src github.githubassets.com; form-action 'self' github.com gist.github.com copilot-workspace.githubnext.com objects-origin.githubusercontent.com; frame-ancestors 'none'; frame-src viewscreen.githubusercontent.com notebooks.githubusercontent.com www.youtube-nocookie.com; img-src 'self' data: blob: github.githubassets.com media.githubusercontent.com camo.githubusercontent.com identicons.github.com avatars.githubusercontent.com private-avatars.githubusercontent.com github-cloud.s3.amazonaws.com objects.githubusercontent.com release-assets.githubusercontent.com secured-user-images.githubusercontent.com user-images.githubusercontent.com private-user-images.githubusercontent.com opengraph.githubassets.com marketplace-screenshots.githubusercontent.com copilotprodattachments.blob.core.windows.net/github-production-copilot-attachments/ github-production-user-asset-6210df.s3.amazonaws.com customer-stories-feed.github.com spotlights-feed.github.com explore-feed.github.com objects-origin.githubusercontent.com *.githubusercontent.com images.ctfassets.net/8aevphvgewt8/; manifest-src 'self'; media-src github.com user-images.githubusercontent.com secured-user-images.githubusercontent.com private-user-images.githubusercontent.com github-production-user-asset-6210df.s3.amazonaws.com gist.github.com github.githubassets.com assets.ctfassets.net/8aevphvgewt8/ videos.ctfassets.net/8aevphvgewt8/; script-src github.githubassets.com; style-src 'unsafe-inline' github.githubassets.com; upgrade-insecure-requests; worker-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/ server: github.com accept-ranges: bytes set-cookie: _gh_sess=OuoC6Uz1Su3kBfAe7Ckvuhz7ZxbF1tcT4kqEkMC2a%2FqG065oh4Bwcj5MrIFvXeYyikJ4qgsAxdF5xHeNcpB00afTJyLFphA%2B1jX%2BGyHFzKtxSKDuETQ1oCsZsn9wTw2cSUOf4rl1MsDYIFX%2F2cy7FjvGhhU6C7Bk4D69TqzL7SS6JWsEDgK5etkkU%2FtvbiWQ39PVzHtgdcqTvQsbhd5JP8FfkvwxGbHlGzNrpftfSb4TfJpgFauONrWVhZxlHklys7RD0ASAT%2Fdq0tiW85d%2FRA%3D%3D--%2B2jKveHvBuvnvcXv--hDi%2FPPnVZWJzfRn3Neve3w%3D%3D; path=/; HttpOnly; secure; SameSite=Lax set-cookie: _octo=GH1.1.686493846.1785089580; expires=Mon, 26 Jul 2027 18:13:00 GMT; domain=.github.com; path=/; secure; SameSite=Lax set-cookie: logged_in=no; expires=Mon, 26 Jul 2027 18:13:00 GMT; domain=.github.com; path=/; HttpOnly; secure; SameSite=Lax x-github-request-id: ECE0:3B0CE5:2C0D599:22499BC:6A664E2C transfer-encoding: chunked
What does each field mean?

Field reference

Sicherheitsbewertung

Aggregierte Bewertung der Sicherheitsheader, gewichtet nach Wirkung: HSTS und CSP fallen am stärksten ins Gewicht. A+ erfordert alle fünf Header korrekt gesetzt; F bedeutet, dass keiner vorhanden ist. Nutzen Sie die Note als schnellen Überblick und sehen Sie sich anschließend die Befunde pro Header an.

HTTP-Protokoll

HTTP/1.1 ist das textbasierte Legacy-Protokoll. HTTP/2 multiplext Streams über eine TCP-Verbindung (Header-Kompression, Server-Push). HTTP/3 läuft über QUIC (UDP) — besser bei verlustreichen oder mobilen Netzen. Moderne Server sollten mindestens HTTP/2 anbieten.

Latenz

Round-Trip von unserem Server zum Ziel bis zum ersten Antwortbyte. Kein CDN-Benchmark — geografische Distanz, TLS-Handshake und Server-Warm-up beeinflussen den Wert. Als grober Frische-Indikator zu verstehen, nicht als produktive Performance-Metrik.

Redirect-Kette

Eine lange Kette (3+ Redirects) schadet SEO und Performance. Klassisches Muster: <code>http://example.com → https://example.com → https://www.example.com</code> — zwei Hops, akzeptabel. Mehr als fünf deuten auf Fehlkonfiguration hin.

Strict-Transport-Security (HSTS)

HSTS weist Browser an, "nie wieder über reines HTTP zu verbinden". <code>max-age=15768000</code> (6 Monate) ist das praktische Minimum; <code>includeSubDomains; preload</code> nimmt an der globalen HSTS-Preload-Liste teil. Einmal vorgeladen ist ein Opt-out für ca. 12 Monate nicht möglich — richten Sie zuerst alles andere ein.

Content-Security-Policy (CSP)

CSP legt fest, woher Skripte, Styles, Bilder und Frames geladen werden dürfen. <code>default-src 'self'</code> ist eine vernünftige Basis; nonce-basiertes <code>script-src</code> ist am stärksten. Vorsicht bei <code>unsafe-inline</code> und <code>unsafe-eval</code> — sie heben den größten Teil des XSS-Schutzes auf. Nutzen Sie report-uri / report-to fürs Monitoring.

X-Frame-Options

Setzen Sie <code>DENY</code>, um Framing komplett zu verbieten, oder <code>SAMEORIGIN</code>, um nur Same-Origin-Frames zuzulassen. Das moderne Pendant ist <code>frame-ancestors</code> in der CSP (reichere Syntax) — eines von beidem genügt unserem Audit.

Referrer-Policy

Bestimmt, was der Browser im <code>Referer</code>-Header sendet. <code>strict-origin-when-cross-origin</code> (Default in modernen Browsern) ist eine gute Basis: volle URL bei Same-Origin, nur Origin bei Cross-Origin, gar nichts bei einem Downgrade. <code>no-referrer</code> entfernt den Referrer komplett; <code>unsafe-url</code> leakt volle URLs auch bei Downgrade — vermeiden.

Permissions-Policy

Nachfolger der Feature-Policy. Erlaubt es, Browser-APIs pro Origin zuzulassen oder zu verbieten: <code>camera=(), microphone=(), geolocation=(self)</code>. Vor allem Defense-in-Depth; wird auch in iframes durchgesetzt — sicherere Voreinstellung für eingebettete Inhalte.

X-Content-Type-Options: nosniff

Ohne diesen Header kann der Browser eine JSON-Antwort als JavaScript ausführen, wenn sie "wie Skript aussieht". <code>X-Content-Type-Options: nosniff</code> erzwingt die Einhaltung des deklarierten Content-Type. Günstig, immer gefahrlos zu aktivieren — es gibt keinen guten Grund, ihn wegzulassen.

Über dieses Tool

Der HTTP Headers Inspector zeigt alle Request- und Response-Header einer Webseite oder API-URL. Wir senden einen HTTP-Request von unserem Frankfurter Server (mit Wahl der Methode: GET, HEAD, POST), folgen optional Redirects, und liefern die vollständige Antwort-Header-Liste — geordnet, kommentiert und in mehreren Standard-Headern interpretiert.

Über die reine Anzeige hinaus liefert das Tool eine Bewertung: Cache-Control und Expires werden ausgewertet (wie lange wird die Antwort wo gecacht?), Security-Header werden geprüft (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy), und die Server-Stack-Identifizierung kommt aus den üblichen verdächtigen Headern (Server, X-Powered-By, X-AspNet-Version, X-Drupal-Cache, etc.).

Wann Sie dieses Tool nutzen sollten

  • Caching-Probleme debuggen. Warum wird diese Antwort 30 Minuten gecacht, obwohl sie dynamisch sein sollte?
  • CORS-Konfiguration prüfen. Sind die richtigen Access-Control-Allow-*-Header gesetzt?
  • Security-Audit. Schickt Ihre Seite alle modernen Security-Header?
  • CDN-Verhalten verifizieren. Welcher Edge bedient Sie, was sagt CF-Cache-Status?

Best-Practice-Header für Production

Eine seriöse Produktivseite setzt mindestens: Strict-Transport-Security (HSTS, mit ausreichender max-age), Content-Security-Policy (CSP, restriktiv konfiguriert), X-Content-Type-Options: nosniff, X-Frame-Options: DENY oder SAMEORIGIN (oder besser CSP frame-ancestors), Referrer-Policy: strict-origin-when-cross-origin. Permissions-Policy ist Sahnehaube. Eine fehlende dieser Header ist kein akuter Bug, aber ein Defense-in-Depth-Versäumnis.

Häufige Fragen

Was ist der Unterschied zwischen Request- und Response-Headern?

Request-Header sendet der Client an den Server (User-Agent, Accept, Cookie, Authorization). Response-Header sendet der Server zurück (Content-Type, Set-Cookie, Cache-Control, Server). Unser Tool zeigt primär Response-Header (denn die kontrolliert der Server-Betreiber) und einen Auszug der gesendeten Request-Header, damit Sie die volle Konversation sehen.

Was ist HSTS und warum ist es wichtig?

HTTP Strict Transport Security weist den Browser an, eine Domain nur noch über HTTPS aufzurufen, auch wenn der Nutzer http:// eingibt. Das schützt vor SSL-Stripping-Angriffen und versehentlichen Klartext-Verbindungen. Ein produktiver HSTS-Header sollte max-age ≥ 6 Monate, includeSubDomains und (optional, mit Preload-Liste) preload enthalten.

Warum sehe ich keinen Server-Header?

Manche Sites entfernen den Server-Header bewusst (Security through obscurity). Andere zeigen nur "nginx" ohne Version, was Best Practice ist — die Version verrät potenzielle Angriffsoberfläche. Cloudflare und Akamai setzen oft eigene Server: cloudflare-Werte, die nur den CDN, nicht den Origin verraten.

Folgt das Tool Redirects?

Optional. Standardmäßig zeigen wir die Header der ersten Antwort, inklusive 3xx-Statuscodes. Mit aktivierter "Follow Redirects"-Option folgen wir bis zu 10 Sprüngen und zeigen die Header jedes Hops separat — gut zur Diagnose komplexer Weiterleitungsketten (www → apex → CDN → app).