Security

HTTP Headers

Bekijk response-headers en audit beveiligingsbeleid.

URL http or https (default https). Up to 3 redirects are followed.
https://github.com/
Status: 200 HTTP/1.1 96 ms
B
Security grade?
Score
82 / 100
Status
200
Protocol?
HTTP/1.1
Latency?
96 ms
Security audit
  • pass Strict-Transport-Security? +25/25
    HSTS is set with a long max-age — browsers will refuse plaintext HTTP for the next 6+ months.
    max-age=31536000; includeSubdomains; preload
  • pass Content-Security-Policy? +25/25
    CSP is set with reasonable defaults — script and style sources are restricted.
    default-src 'none'; base-uri 'self'; child-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/; connect-src 'self' uploads.github.com www.githubstatus.com collector.github.com raw.githubusercontent.com api.github.com github-cloud.s3.amazonaws.com github-production-repository-file-5c1aeb.s3.amazonaws.com github-production-upload-manifest-file-7fdce7.s3.amazonaws.com github-production-user-asset-6210df.s3.amazonaws.com *.rel.tunnels.api.visualstudio.com wss://*.rel.tunnels.api.visualstudio.com github.githubassets.com objects-origin.githubusercontent.com copilot-proxy.githubusercontent.com proxy.individual.githubcopilot.com proxy.business.githubcopilot.com proxy.enterprise.githubcopilot.com *.actions.githubusercontent.com wss://*.actions.githubusercontent.com productionresultssa0.blob.core.windows.net productionresultssa1.blob.core.windows.net productionresultssa2.blob.core.windows.net productionresultssa3.blob.core.windows.net productionresultssa4.blob.core.windows.net productionresultssa5.blob.core.windows.net productionresultssa6.blob.core.windows.net productionresultssa7.blob.core.windows.net productionresultssa8.blob.core.windows.net productionresultssa9.blob.core.windows.net productionresultssa10.blob.core.windows.net productionresultssa11.blob.core.windows.net productionresultssa12.blob.core.windows.net productionresultssa13.blob.core.windows.net productionresultssa14.blob.core.windows.net productionresultssa15.blob.core.windows.net productionresultssa16.blob.core.windows.net productionresultssa17.blob.core.windows.net productionresultssa18.blob.core.windows.net productionresultssa19.blob.core.windows.net github-production-repository-image-32fea6.s3.amazonaws.com github-production-release-asset-2e65be.s3.amazonaws.com insights.github.com wss://alive.github.com wss://alive-staging.github.com api.githubcopilot.com api.individual.githubcopilot.com api.business.githubcopilot.com api.enterprise.githubcopilot.com wss://production-copilot-host.webpubsub.azure.com edge.fullstory.com rs.fullstory.com; font-src github.githubassets.com; form-action 'self' github.com gist.github.com copilot-workspace.githubnext.com objects-origin.githubusercontent.com; frame-ancestors 'none'; frame-src viewscreen.githubusercontent.com notebooks.githubusercontent.com www.youtube-nocookie.com; img-src 'self' data: blob: github.githubassets.com media.githubusercontent.com camo.githubusercontent.com identicons.github.com avatars.githubusercontent.com private-avatars.githubusercontent.com github-cloud.s3.amazonaws.com objects.githubusercontent.com release-assets.githubusercontent.com secured-user-images.githubusercontent.com user-images.githubusercontent.com private-user-images.githubusercontent.com opengraph.githubassets.com marketplace-screenshots.githubusercontent.com copilotprodattachments.blob.core.windows.net/github-production-copilot-attachments/ github-production-user-asset-6210df.s3.amazonaws.com customer-stories-feed.github.com spotlights-feed.github.com explore-feed.github.com objects-origin.githubusercontent.com *.githubusercontent.com images.ctfassets.net/8aevphvgewt8/; manifest-src 'self'; media-src github.com user-images.githubusercontent.com secured-user-images.githubusercontent.com private-user-images.githubusercontent.com github-production-user-asset-6210df.s3.amazonaws.com gist.github.com github.githubassets.com assets.ctfassets.net/8aevphvgewt8/ videos.ctfassets.net/8aevphvgewt8/; script-src github.githubassets.com; style-src 'unsafe-inline' github.githubassets.com; upgrade-insecure-requests; worker-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/
  • pass X-Frame-Options / frame-ancestors? +15/15
    Clickjacking is blocked — page cannot be embedded in third-party iframes.
    deny
  • pass X-Content-Type-Options +10/10
    nosniff is set — browsers will not MIME-sniff non-script responses as JavaScript.
    nosniff
  • warn Referrer-Policy? +7/15
    Referrer policy leaks parts of the URL cross-origin — switch to strict-origin-when-cross-origin.
    origin-when-cross-origin, strict-origin-when-cross-origin
  • fail Permissions-Policy? +0/10
    No Permissions-Policy — third-party iframes can request sensitive features without restriction.
Response headers
date: Sun, 26 Jul 2026 18:12:49 GMT content-type: text/html; charset=utf-8 vary: X-PJAX, X-PJAX-Container, Turbo-Visit, Turbo-Frame, X-Requested-With, X-GitHub-Client-Version, Accept-Language, Sec-Fetch-Site,Accept-Encoding, Accept, X-Requested-With content-language: en-US etag: W/"3f956f090971482e9a8d1fe36c4b9d2c" cache-control: max-age=0, private, must-revalidate strict-transport-security: max-age=31536000; includeSubdomains; preload x-frame-options: deny x-content-type-options: nosniff x-xss-protection: 0 referrer-policy: origin-when-cross-origin, strict-origin-when-cross-origin content-security-policy: default-src 'none'; base-uri 'self'; child-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/; connect-src 'self' uploads.github.com www.githubstatus.com collector.github.com raw.githubusercontent.com api.github.com github-cloud.s3.amazonaws.com github-production-repository-file-5c1aeb.s3.amazonaws.com github-production-upload-manifest-file-7fdce7.s3.amazonaws.com github-production-user-asset-6210df.s3.amazonaws.com *.rel.tunnels.api.visualstudio.com wss://*.rel.tunnels.api.visualstudio.com github.githubassets.com objects-origin.githubusercontent.com copilot-proxy.githubusercontent.com proxy.individual.githubcopilot.com proxy.business.githubcopilot.com proxy.enterprise.githubcopilot.com *.actions.githubusercontent.com wss://*.actions.githubusercontent.com productionresultssa0.blob.core.windows.net productionresultssa1.blob.core.windows.net productionresultssa2.blob.core.windows.net productionresultssa3.blob.core.windows.net productionresultssa4.blob.core.windows.net productionresultssa5.blob.core.windows.net productionresultssa6.blob.core.windows.net productionresultssa7.blob.core.windows.net productionresultssa8.blob.core.windows.net productionresultssa9.blob.core.windows.net productionresultssa10.blob.core.windows.net productionresultssa11.blob.core.windows.net productionresultssa12.blob.core.windows.net productionresultssa13.blob.core.windows.net productionresultssa14.blob.core.windows.net productionresultssa15.blob.core.windows.net productionresultssa16.blob.core.windows.net productionresultssa17.blob.core.windows.net productionresultssa18.blob.core.windows.net productionresultssa19.blob.core.windows.net github-production-repository-image-32fea6.s3.amazonaws.com github-production-release-asset-2e65be.s3.amazonaws.com insights.github.com wss://alive.github.com wss://alive-staging.github.com api.githubcopilot.com api.individual.githubcopilot.com api.business.githubcopilot.com api.enterprise.githubcopilot.com wss://production-copilot-host.webpubsub.azure.com edge.fullstory.com rs.fullstory.com; font-src github.githubassets.com; form-action 'self' github.com gist.github.com copilot-workspace.githubnext.com objects-origin.githubusercontent.com; frame-ancestors 'none'; frame-src viewscreen.githubusercontent.com notebooks.githubusercontent.com www.youtube-nocookie.com; img-src 'self' data: blob: github.githubassets.com media.githubusercontent.com camo.githubusercontent.com identicons.github.com avatars.githubusercontent.com private-avatars.githubusercontent.com github-cloud.s3.amazonaws.com objects.githubusercontent.com release-assets.githubusercontent.com secured-user-images.githubusercontent.com user-images.githubusercontent.com private-user-images.githubusercontent.com opengraph.githubassets.com marketplace-screenshots.githubusercontent.com copilotprodattachments.blob.core.windows.net/github-production-copilot-attachments/ github-production-user-asset-6210df.s3.amazonaws.com customer-stories-feed.github.com spotlights-feed.github.com explore-feed.github.com objects-origin.githubusercontent.com *.githubusercontent.com images.ctfassets.net/8aevphvgewt8/; manifest-src 'self'; media-src github.com user-images.githubusercontent.com secured-user-images.githubusercontent.com private-user-images.githubusercontent.com github-production-user-asset-6210df.s3.amazonaws.com gist.github.com github.githubassets.com assets.ctfassets.net/8aevphvgewt8/ videos.ctfassets.net/8aevphvgewt8/; script-src github.githubassets.com; style-src 'unsafe-inline' github.githubassets.com; upgrade-insecure-requests; worker-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/ server: github.com accept-ranges: bytes set-cookie: _gh_sess=OuoC6Uz1Su3kBfAe7Ckvuhz7ZxbF1tcT4kqEkMC2a%2FqG065oh4Bwcj5MrIFvXeYyikJ4qgsAxdF5xHeNcpB00afTJyLFphA%2B1jX%2BGyHFzKtxSKDuETQ1oCsZsn9wTw2cSUOf4rl1MsDYIFX%2F2cy7FjvGhhU6C7Bk4D69TqzL7SS6JWsEDgK5etkkU%2FtvbiWQ39PVzHtgdcqTvQsbhd5JP8FfkvwxGbHlGzNrpftfSb4TfJpgFauONrWVhZxlHklys7RD0ASAT%2Fdq0tiW85d%2FRA%3D%3D--%2B2jKveHvBuvnvcXv--hDi%2FPPnVZWJzfRn3Neve3w%3D%3D; path=/; HttpOnly; secure; SameSite=Lax set-cookie: _octo=GH1.1.686493846.1785089580; expires=Mon, 26 Jul 2027 18:13:00 GMT; domain=.github.com; path=/; secure; SameSite=Lax set-cookie: logged_in=no; expires=Mon, 26 Jul 2027 18:13:00 GMT; domain=.github.com; path=/; HttpOnly; secure; SameSite=Lax x-github-request-id: ECE0:3B0CE5:2C0D599:22499BC:6A664E2C transfer-encoding: chunked
What does each field mean?

Field reference

Securitycijfer

Aggregaatscore van security-headers, gewogen naar impact: HSTS en CSP wegen het zwaarst. A+ vereist alle vijf headers correct ingesteld; F betekent dat er geen aanwezig zijn. Gebruik als snelle eerste indicator en duik daarna de per-header bevindingen in.

HTTP-protocol

HTTP/1.1 is het legacy tekstprotocol. HTTP/2 multiplext streams over één TCP-verbinding (headercompressie, server push). HTTP/3 draait over QUIC (UDP) — beter op verlies- of mobiele netwerken. Moderne servers horen minstens HTTP/2 aan te bieden.

Latency

Round-trip van onze server naar het doel tot de eerste responsbyte arriveert. Geen CDN-benchmark — geografische afstand, TLS-handshake en server-warm-up spelen mee. Gebruik als grove versheidsindicator, niet als productie-performancedata.

Redirect-keten

Een lange keten (3+ redirects) schaadt SEO en performance. Het klassieke patroon is <code>http://example.com → https://example.com → https://www.example.com</code>: twee hops, acceptabel. Meer dan vijf duidt op een misconfiguratie.

Strict-Transport-Security (HSTS)

HSTS zegt tegen browsers: "verbind nooit meer met mij over plain HTTP". <code>max-age=15768000</code> (6 maanden) is het praktische minimum; <code>includeSubDomains; preload</code> opteert in op de globale HSTS preload-lijst. Eenmaal preloaded kunt u zo'n 12 maanden niet meer terug — zet eerst al het overige goed.

Content-Security-Policy (CSP)

CSP whitelist waar scripts, styles, afbeeldingen en frames vandaan mogen laden. <code>default-src 'self'</code> is een verstandige baseline; nonce-based <code>script-src</code> is het sterkst. Pas op met <code>unsafe-inline</code> en <code>unsafe-eval</code> — die ontkrachten de XSS-bescherming van CSP. Gebruik report-uri / report-to voor monitoring.

X-Frame-Options

Stel <code>DENY</code> in om framing volledig te verbieden, of <code>SAMEORIGIN</code> om alleen same-origin frames toe te staan. Het moderne equivalent is <code>frame-ancestors</code> in CSP (rijkere syntax) — beide voldoen aan onze audit.

Referrer-Policy

Bepaalt wat de browser in de <code>Referer</code>-header meestuurt. <code>strict-origin-when-cross-origin</code> (standaard in moderne browsers) is een goede baseline: volledige URL same-origin, enkel origin cross-origin, niets bij downgrade. <code>no-referrer</code> verwijdert referrer volledig; <code>unsafe-url</code> lekt volledige URL's bij downgrade — vermijden.

Permissions-Policy

Opvolger van Feature-Policy. Laat u browser-API's per origin toestaan of weigeren: <code>camera=(), microphone=(), geolocation=(self)</code>. Vooral defense-in-depth; afgedwongen op iframes, dus veiliger gedrag voor ingebedde content.

X-Content-Type-Options: nosniff

Zonder deze header kan een browser een JSON-respons als JavaScript uitvoeren als het "op script lijkt". <code>X-Content-Type-Options: nosniff</code> dwingt af dat het opgegeven Content-Type wordt gerespecteerd. Goedkoop, altijd veilig om aan te zetten — er is geen goede reden om dit weg te laten.

Over deze tool

HTTP Headers haalt uw URL op met een echte HTTPS-aanvraag, vangt elke header in het antwoord op (en elk tussenliggend antwoord langs een redirect-keten), en draait het resultaat door een beveiligingsaudit die de moderne hardening-headers dekt: Strict-Transport-Security, Content-Security-Policy, X-Frame-Options / CSP frame-ancestors, X-Content-Type-Options, Referrer-Policy en Permissions-Policy. Elke header wordt gecontroleerd op aanwezigheid, waarde-saniteit en best-practice-gaten.

Naast de audit tonen we elke header letterlijk zodat u caching-beleid (Cache-Control, ETag, Vary), CDN-tracing (CF-Ray, X-Cache, X-Served-By), compressie (Content-Encoding: br/gzip) en alle aangepaste headers die uw stack uitzendt kunt bevestigen. De HTTP-methode (GET of HEAD), HTTP-versie die werd onderhandeld (HTTP/1.1, HTTP/2, HTTP/3) en TLS-versie worden in de request-balk gerapporteerd.

Wanneer gebruikt u deze tool

  • Security hardening. Bevestig vóór live-gaan dat HSTS, CSP en de rest met veilige waarden zijn ingesteld — Mozilla Observatory-baseline minimaal.
  • Cache debuggen. Zie precies welke Cache-Control en Vary uw CMS of framework uitzendt — veelvoorkomende oorzaak van "oude versie blijft hangen".
  • Redirect-keten-audits. Spot toevallige 302-dan-301-ketens, HTTP-naar-HTTPS-naar-andere-host-loops en ontbrekende canonicalisatie.
  • CDN-gedrag. Bevestig dat Cloudflare/Fastly/CloudFront werkelijk cachet wat u denkt door de Age, X-Cache en CDN-specifieke headers te lezen.

Wat onze beveiligingsaudit dekt

Voor elk van de zes hardening-headers rapporteren we: aanwezig of ontbrekend, de werkelijke waarde, en een kort oordeel ("goed", "moet worden verstrakt", "kwetsbaar"). HSTS zonder includeSubDomains, CSP met unsafe-inline of Referrer-Policy op default krijgen een vlag. We vertellen u nooit het "perfecte" beleid omdat elke site anders is — maar we vertellen u welke knoppen nog op de fabrieksinstelling staan.

Veelgestelde vragen

Wat is HSTS en waarom is het belangrijk?

Strict-Transport-Security vertelt de browser "gebruik altijd HTTPS voor dit domein, ook als de gebruiker http:// typte of op een http://-link klikte". Eenmaal ingesteld met een redelijke max-age (typisch 31536000 = 1 jaar), voorkomt het SSL-stripping-aanvallen op volgende bezoeken. includeSubDomains toevoegen breidt de bescherming uit naar elk subdomein — sterke standaard voor de meeste sites, maar zorg dat alle subdomeinen werkelijk HTTPS ondersteunen.

Mijn CSP ontbreekt — hoe gevaarlijk is dat?

Zonder CSP voert elke XSS-bug op uw site met volle kracht uit: het kan cookies exfiltreren, aanvallers-bestuurde scripts laden of de DOM herschrijven. Een startende CSP van default-src 'self' blokkeert de meest gangbare XSS-payloads (inline-scripts, externe script-loads) tegen bijna nul kosten. Strakkere policies die inline-scripts volledig verbieden vereisen refactoring maar bieden veel sterkere bescherming.

Volgt u redirects?

Ja — tot vijf hops. Elke stap wordt getoond met zijn methode, status, locatie en headers, zodat u gemengde-protocol-hops (HTTP→HTTPS), ontbrekende canonicalisatie (apex vs www) of toevallige loops kunt opsporen. De meeste productie-sites zouden hoogstens één keer moeten redirecten (HTTP → HTTPS) en daarna content serveren; meer dan twee hops is meestal een teken van overlappende rewrite-regels.

Waarom toont de tool HTTP/2 zelfs als ik HTTP/3 heb geconfigureerd?

HTTP/3 (QUIC over UDP) vereist dat de client opt-in geeft via de Alt-Svc-header op de eerste verbinding. Onze checker gebruikt standaard HTTP/2 over TCP, wat de meeste HTTP-clients vandaag nog doen; als uw server HTTP/3 adverteert in Alt-Svc, ziet u die header in het resultaat, maar het antwoord zelf is nog steeds over HTTP/2. De aanwezigheid van Alt-Svc is het juiste om naar te zoeken.