Headers included in the check
The tool reports the final response status and selected metadata, follows a limited redirect chain, and checks for Strict-Transport-Security (HSTS), Content-Security-Policy (CSP), X-Content-Type-Options, X-Frame-Options, Referrer-Policy and Permissions-Policy.
A missing header is shown as missing; that does not alone prove a vulnerability. Correct values depend on how the site is built, its content and its threat model. Header presence does not confirm the policy is configured correctly.
Safe and authorized use
The checker makes an HTTP request to the public target from the ATROXIS service. Use it only for sites you own or are authorized to assess. Some sites block automated requests or behave differently for scanners.