Paste response headers and get a security grade with fixes.
Everything is analysed locally in your browser — the headers you paste are never sent anywhere. This tool cannot fetch a URL for you (browsers block cross-origin header reads), so copy the headers in yourself.
Treat these as a starting point. A Content-Security-Policy in particular must be tailored to the assets your site actually loads — deploy it in report-only mode first.