Protected By Tyrant Softwares

Security Header Playground

Build and test HTTP security headers with live scoring

How it works: start from a preset, toggle each header and tune its value, and watch the security score update as you go. When the configuration looks right, copy the response headers and add them to your server. New to these headers? Read the guide first — it explains what each one defends against.
0
Security Score

Header Configuration

Content-Security-Policy

Controls which resources can load. The most powerful XSS defense.

Strict-Transport-Security (HSTS)

Forces HTTPS, prevents protocol downgrade attacks.

X-Frame-Options

Prevents your site from being embedded in iframes (clickjacking defense).

X-Content-Type-Options

Prevents browsers from MIME-sniffing content types.

Referrer-Policy

Controls how much referrer info is shared when navigating away.

Permissions-Policy

Controls which browser features (camera, mic, geolocation) the site can use.

X-XSS-Protection

Legacy XSS filter (mostly replaced by CSP, but still useful).

Response Headers