Security

HTTP Headers

Wyświetl nagłówki odpowiedzi i audytuj polityki bezpieczeństwa.

URL http or https (default https). Up to 3 redirects are followed.
https://github.com/
Status: 200 HTTP/1.1 96 ms
B
Security grade?
Score
82 / 100
Status
200
Protocol?
HTTP/1.1
Latency?
96 ms
Security audit
  • pass Strict-Transport-Security? +25/25
    HSTS is set with a long max-age — browsers will refuse plaintext HTTP for the next 6+ months.
    max-age=31536000; includeSubdomains; preload
  • pass Content-Security-Policy? +25/25
    CSP is set with reasonable defaults — script and style sources are restricted.
    default-src 'none'; base-uri 'self'; child-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/; connect-src 'self' uploads.github.com www.githubstatus.com collector.github.com raw.githubusercontent.com api.github.com github-cloud.s3.amazonaws.com github-production-repository-file-5c1aeb.s3.amazonaws.com github-production-upload-manifest-file-7fdce7.s3.amazonaws.com github-production-user-asset-6210df.s3.amazonaws.com *.rel.tunnels.api.visualstudio.com wss://*.rel.tunnels.api.visualstudio.com github.githubassets.com objects-origin.githubusercontent.com copilot-proxy.githubusercontent.com proxy.individual.githubcopilot.com proxy.business.githubcopilot.com proxy.enterprise.githubcopilot.com *.actions.githubusercontent.com wss://*.actions.githubusercontent.com productionresultssa0.blob.core.windows.net productionresultssa1.blob.core.windows.net productionresultssa2.blob.core.windows.net productionresultssa3.blob.core.windows.net productionresultssa4.blob.core.windows.net productionresultssa5.blob.core.windows.net productionresultssa6.blob.core.windows.net productionresultssa7.blob.core.windows.net productionresultssa8.blob.core.windows.net productionresultssa9.blob.core.windows.net productionresultssa10.blob.core.windows.net productionresultssa11.blob.core.windows.net productionresultssa12.blob.core.windows.net productionresultssa13.blob.core.windows.net productionresultssa14.blob.core.windows.net productionresultssa15.blob.core.windows.net productionresultssa16.blob.core.windows.net productionresultssa17.blob.core.windows.net productionresultssa18.blob.core.windows.net productionresultssa19.blob.core.windows.net github-production-repository-image-32fea6.s3.amazonaws.com github-production-release-asset-2e65be.s3.amazonaws.com insights.github.com wss://alive.github.com wss://alive-staging.github.com api.githubcopilot.com api.individual.githubcopilot.com api.business.githubcopilot.com api.enterprise.githubcopilot.com wss://production-copilot-host.webpubsub.azure.com edge.fullstory.com rs.fullstory.com; font-src github.githubassets.com; form-action 'self' github.com gist.github.com copilot-workspace.githubnext.com objects-origin.githubusercontent.com; frame-ancestors 'none'; frame-src viewscreen.githubusercontent.com notebooks.githubusercontent.com www.youtube-nocookie.com; img-src 'self' data: blob: github.githubassets.com media.githubusercontent.com camo.githubusercontent.com identicons.github.com avatars.githubusercontent.com private-avatars.githubusercontent.com github-cloud.s3.amazonaws.com objects.githubusercontent.com release-assets.githubusercontent.com secured-user-images.githubusercontent.com user-images.githubusercontent.com private-user-images.githubusercontent.com opengraph.githubassets.com marketplace-screenshots.githubusercontent.com copilotprodattachments.blob.core.windows.net/github-production-copilot-attachments/ github-production-user-asset-6210df.s3.amazonaws.com customer-stories-feed.github.com spotlights-feed.github.com explore-feed.github.com objects-origin.githubusercontent.com *.githubusercontent.com images.ctfassets.net/8aevphvgewt8/; manifest-src 'self'; media-src github.com user-images.githubusercontent.com secured-user-images.githubusercontent.com private-user-images.githubusercontent.com github-production-user-asset-6210df.s3.amazonaws.com gist.github.com github.githubassets.com assets.ctfassets.net/8aevphvgewt8/ videos.ctfassets.net/8aevphvgewt8/; script-src github.githubassets.com; style-src 'unsafe-inline' github.githubassets.com; upgrade-insecure-requests; worker-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/
  • pass X-Frame-Options / frame-ancestors? +15/15
    Clickjacking is blocked — page cannot be embedded in third-party iframes.
    deny
  • pass X-Content-Type-Options +10/10
    nosniff is set — browsers will not MIME-sniff non-script responses as JavaScript.
    nosniff
  • warn Referrer-Policy? +7/15
    Referrer policy leaks parts of the URL cross-origin — switch to strict-origin-when-cross-origin.
    origin-when-cross-origin, strict-origin-when-cross-origin
  • fail Permissions-Policy? +0/10
    No Permissions-Policy — third-party iframes can request sensitive features without restriction.
Response headers
date: Sun, 26 Jul 2026 18:12:49 GMT content-type: text/html; charset=utf-8 vary: X-PJAX, X-PJAX-Container, Turbo-Visit, Turbo-Frame, X-Requested-With, X-GitHub-Client-Version, Accept-Language, Sec-Fetch-Site,Accept-Encoding, Accept, X-Requested-With content-language: en-US etag: W/"3f956f090971482e9a8d1fe36c4b9d2c" cache-control: max-age=0, private, must-revalidate strict-transport-security: max-age=31536000; includeSubdomains; preload x-frame-options: deny x-content-type-options: nosniff x-xss-protection: 0 referrer-policy: origin-when-cross-origin, strict-origin-when-cross-origin content-security-policy: default-src 'none'; base-uri 'self'; child-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/; connect-src 'self' uploads.github.com www.githubstatus.com collector.github.com raw.githubusercontent.com api.github.com github-cloud.s3.amazonaws.com github-production-repository-file-5c1aeb.s3.amazonaws.com github-production-upload-manifest-file-7fdce7.s3.amazonaws.com github-production-user-asset-6210df.s3.amazonaws.com *.rel.tunnels.api.visualstudio.com wss://*.rel.tunnels.api.visualstudio.com github.githubassets.com objects-origin.githubusercontent.com copilot-proxy.githubusercontent.com proxy.individual.githubcopilot.com proxy.business.githubcopilot.com proxy.enterprise.githubcopilot.com *.actions.githubusercontent.com wss://*.actions.githubusercontent.com productionresultssa0.blob.core.windows.net productionresultssa1.blob.core.windows.net productionresultssa2.blob.core.windows.net productionresultssa3.blob.core.windows.net productionresultssa4.blob.core.windows.net productionresultssa5.blob.core.windows.net productionresultssa6.blob.core.windows.net productionresultssa7.blob.core.windows.net productionresultssa8.blob.core.windows.net productionresultssa9.blob.core.windows.net productionresultssa10.blob.core.windows.net productionresultssa11.blob.core.windows.net productionresultssa12.blob.core.windows.net productionresultssa13.blob.core.windows.net productionresultssa14.blob.core.windows.net productionresultssa15.blob.core.windows.net productionresultssa16.blob.core.windows.net productionresultssa17.blob.core.windows.net productionresultssa18.blob.core.windows.net productionresultssa19.blob.core.windows.net github-production-repository-image-32fea6.s3.amazonaws.com github-production-release-asset-2e65be.s3.amazonaws.com insights.github.com wss://alive.github.com wss://alive-staging.github.com api.githubcopilot.com api.individual.githubcopilot.com api.business.githubcopilot.com api.enterprise.githubcopilot.com wss://production-copilot-host.webpubsub.azure.com edge.fullstory.com rs.fullstory.com; font-src github.githubassets.com; form-action 'self' github.com gist.github.com copilot-workspace.githubnext.com objects-origin.githubusercontent.com; frame-ancestors 'none'; frame-src viewscreen.githubusercontent.com notebooks.githubusercontent.com www.youtube-nocookie.com; img-src 'self' data: blob: github.githubassets.com media.githubusercontent.com camo.githubusercontent.com identicons.github.com avatars.githubusercontent.com private-avatars.githubusercontent.com github-cloud.s3.amazonaws.com objects.githubusercontent.com release-assets.githubusercontent.com secured-user-images.githubusercontent.com user-images.githubusercontent.com private-user-images.githubusercontent.com opengraph.githubassets.com marketplace-screenshots.githubusercontent.com copilotprodattachments.blob.core.windows.net/github-production-copilot-attachments/ github-production-user-asset-6210df.s3.amazonaws.com customer-stories-feed.github.com spotlights-feed.github.com explore-feed.github.com objects-origin.githubusercontent.com *.githubusercontent.com images.ctfassets.net/8aevphvgewt8/; manifest-src 'self'; media-src github.com user-images.githubusercontent.com secured-user-images.githubusercontent.com private-user-images.githubusercontent.com github-production-user-asset-6210df.s3.amazonaws.com gist.github.com github.githubassets.com assets.ctfassets.net/8aevphvgewt8/ videos.ctfassets.net/8aevphvgewt8/; script-src github.githubassets.com; style-src 'unsafe-inline' github.githubassets.com; upgrade-insecure-requests; worker-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/ server: github.com accept-ranges: bytes set-cookie: _gh_sess=OuoC6Uz1Su3kBfAe7Ckvuhz7ZxbF1tcT4kqEkMC2a%2FqG065oh4Bwcj5MrIFvXeYyikJ4qgsAxdF5xHeNcpB00afTJyLFphA%2B1jX%2BGyHFzKtxSKDuETQ1oCsZsn9wTw2cSUOf4rl1MsDYIFX%2F2cy7FjvGhhU6C7Bk4D69TqzL7SS6JWsEDgK5etkkU%2FtvbiWQ39PVzHtgdcqTvQsbhd5JP8FfkvwxGbHlGzNrpftfSb4TfJpgFauONrWVhZxlHklys7RD0ASAT%2Fdq0tiW85d%2FRA%3D%3D--%2B2jKveHvBuvnvcXv--hDi%2FPPnVZWJzfRn3Neve3w%3D%3D; path=/; HttpOnly; secure; SameSite=Lax set-cookie: _octo=GH1.1.686493846.1785089580; expires=Mon, 26 Jul 2027 18:13:00 GMT; domain=.github.com; path=/; secure; SameSite=Lax set-cookie: logged_in=no; expires=Mon, 26 Jul 2027 18:13:00 GMT; domain=.github.com; path=/; HttpOnly; secure; SameSite=Lax x-github-request-id: ECE0:3B0CE5:2C0D599:22499BC:6A664E2C transfer-encoding: chunked
What does each field mean?

Field reference

Ocena bezpieczeństwa

Zagregowany wynik nagłówków bezpieczeństwa ważony wpływem: HSTS i CSP ważą najwięcej. A+ wymaga poprawnego ustawienia wszystkich pięciu nagłówków; F oznacza brak jakichkolwiek. Użyj jako szybkiej miary pierwszego rzutu oka, a potem zajrzyj do szczegółów per-nagłówek poniżej.

Protokół HTTP

HTTP/1.1 to przestarzały protokół tekstowy. HTTP/2 multipleksuje strumienie po jednym połączeniu TCP (kompresja nagłówków, server push). HTTP/3 działa na QUIC (UDP) — lepiej na łączach niestabilnych i mobilnych. Nowoczesny serwer powinien udostępniać co najmniej HTTP/2.

Opóźnienie

Round-trip od naszego serwera do celu, aż do pierwszego bajtu odpowiedzi. To nie benchmark CDN — wpływają na niego odległość geograficzna, TLS handshake i rozgrzewka serwera. Traktuj jako orientacyjny sygnał świeżości, a nie produkcyjne dane wydajności.

Łańcuch przekierowań

Długi łańcuch (3+ przekierowania) szkodzi SEO i wydajności. Klasyczny wzorzec to <code>http://example.com → https://example.com → https://www.example.com</code>: dwa hopy, akceptowalnie. Powyżej pięciu — błąd konfiguracji.

Strict-Transport-Security (HSTS)

HSTS mówi przeglądarce: "nigdy więcej nie łącz się ze mną po zwykłym HTTP". <code>max-age=15768000</code> (6 miesięcy) to praktyczne minimum; <code>includeSubDomains; preload</code> dopisuje domenę do globalnej listy preload. Po wpisaniu na listę nie da się jej opuścić przez ~12 miesięcy — najpierw skonfiguruj resztę.

Content-Security-Policy (CSP)

CSP określa, skąd mogą się ładować skrypty, style, obrazy i ramki. <code>default-src 'self'</code> to rozsądny baseline; oparte na nonce <code>script-src</code> jest najmocniejsze. Uwaga na <code>unsafe-inline</code> i <code>unsafe-eval</code> — niemal niwelują ochronę CSP przed XSS. Używaj report-uri / report-to do monitoringu.

X-Frame-Options

Ustaw <code>DENY</code>, aby całkowicie zabronić ramek, lub <code>SAMEORIGIN</code>, aby zezwolić tylko na ramki tego samego pochodzenia. Nowoczesnym odpowiednikiem jest <code>frame-ancestors</code> w CSP (bogatsza składnia) — każdy z tych dwóch spełnia nasz audyt.

Referrer-Policy

Określa, co przeglądarka wysyła w nagłówku <code>Referer</code>. <code>strict-origin-when-cross-origin</code> (domyślne w nowoczesnych przeglądarkach) to dobry baseline: pełny URL przy same-origin, jedynie origin przy cross-origin, nic przy downgrade. <code>no-referrer</code> usuwa referer całkowicie; <code>unsafe-url</code> wycieka pełne URL-e przy downgrade — unikać.

Permissions-Policy

Następca Feature-Policy. Pozwala zezwalać / zabraniać API przeglądarki per-origin: <code>camera=(), microphone=(), geolocation=(self)</code>. Głównie defense-in-depth; egzekwowane na iframe, więc bezpieczniejsze zachowanie dla osadzonej treści.

X-Content-Type-Options: nosniff

Bez tego nagłówka przeglądarka może wykonać odpowiedź JSON jako JavaScript, jeśli "wygląda jak skrypt". Ustawienie <code>X-Content-Type-Options: nosniff</code> wymusza honorowanie zadeklarowanego Content-Type. Tani, zawsze bezpieczny do włączenia — nie ma dobrego powodu, by go pomijać.

O tym narzędziu

HTTP Headers pobiera Twój URL prawdziwym żądaniem HTTPS, przechwytuje każdy nagłówek odpowiedzi (oraz każdą pośrednią odpowiedź na trasie przekierowań) i przepuszcza wynik przez audyt bezpieczeństwa pokrywający nowoczesne nagłówki hardeningu: Strict-Transport-Security, Content-Security-Policy, X-Frame-Options / CSP frame-ancestors, X-Content-Type-Options, Referrer-Policy i Permissions-Policy. Każdy nagłówek jest sprawdzany pod kątem obecności, sensowności wartości i luk względem best practices.

Poza audytem wymieniamy każdy nagłówek dosłownie, byś mógł potwierdzić politykę cache'owania (Cache-Control, ETag, Vary), śledzenie CDN (CF-Ray, X-Cache, X-Served-By), kompresję (Content-Encoding: br/gzip) i wszelkie własne nagłówki, które emituje Twój stack. Metoda HTTP (GET lub HEAD), negocjowana wersja HTTP (HTTP/1.1, HTTP/2, HTTP/3) i wersja TLS są raportowane w pasku żądania.

Kiedy używać tego narzędzia

  • Hardening bezpieczeństwa. Przed produkcją potwierdź, że HSTS, CSP i reszta są ustawione na bezpieczne wartości — minimum baseline Mozilla Observatory.
  • Debugowanie cache. Zobacz dokładnie, jakie Cache-Control i Vary emituje Twój CMS lub framework — częsta przyczyna "stara wersja się trzyma".
  • Audyty łańcuchów przekierowań. Wykryj przypadkowe łańcuchy 302-potem-301, pętle HTTP-do-HTTPS-do-innego-hosta i brakującą kanonizację.
  • Zachowanie CDN. Potwierdź, że Cloudflare/Fastly/CloudFront faktycznie cache'uje to, co myślisz, czytając nagłówki Age, X-Cache i specyficzne dla CDN.

Co pokrywa nasz audyt bezpieczeństwa

Dla każdego z sześciu nagłówków hardeningu raportujemy: obecny lub brakujący, rzeczywistą wartość i krótki werdykt ("good", "needs tightening", "vulnerable"). HSTS bez includeSubDomains, CSP z unsafe-inline lub Referrer-Policy pozostawiony na default są flagowane. Nigdy nie mówimy "idealnej" polityki, bo każda strona jest inna — ale mówimy, które pokrętła nadal są na ustawieniu fabrycznym.

Najczęstsze pytania

Co to jest HSTS i dlaczego ma znaczenie?

Strict-Transport-Security mówi przeglądarce "zawsze używaj HTTPS dla tej domeny, nawet jeśli użytkownik wpisał http:// lub kliknął link http://". Raz ustawione z rozsądnym max-age (typowo 31536000 = 1 rok), zapobiega atakom SSL-stripping przy kolejnych wizytach. Dodanie includeSubDomains rozszerza ochronę na każdą subdomenę — mocny default dla większości stron, ale upewnij się najpierw, że wszystkie naprawdę obsługują HTTPS.

Brakuje mi CSP — jak bardzo to niebezpieczne?

Bez CSP każda dziura XSS na Twojej stronie wykonuje się z pełną mocą: może wycieknąć ciasteczka, załadować skrypty kontrolowane przez atakującego lub przepisać DOM. Startowy CSP default-src 'self' blokuje najpopularniejsze ładunki XSS (inline skrypty, zewnętrzne ładowanie skryptów) niemal bezkosztowo. Bardziej restrykcyjne polityki zakazujące inline skryptów wymagają refaktoryzacji, ale dają znacznie silniejszą ochronę.

Czy podążacie za przekierowaniami?

Tak — do pięciu hopów. Każdy krok jest pokazany z metodą, statusem, location i nagłówkami, byś mógł wykryć hopy mieszanego protokołu (HTTP→HTTPS), brakującą kanonizację (apex vs www) lub przypadkowe pętle. Większość produkcyjnych stron powinna przekierowywać najwyżej raz (HTTP → HTTPS), a potem serwować zawartość; więcej niż dwa hopy to zwykle znak nakładających się reguł rewrite.

Dlaczego narzędzie pokazuje HTTP/2, choć skonfigurowałem HTTP/3?

HTTP/3 (QUIC nad UDP) wymaga od klienta opt-in poprzez nagłówek Alt-Svc przy pierwszym połączeniu. Nasz checker używa domyślnie HTTP/2 nad TCP, co wciąż robi większość klientów HTTP; jeśli Twój serwer ogłasza HTTP/3 w Alt-Svc, zobaczysz ten nagłówek w wyniku, ale sama odpowiedź pozostanie na HTTP/2. Obecność Alt-Svc to właściwa rzecz do sprawdzenia.