Security Headers We Monitor
Comprehensive checks for all important security headers
Strict-Transport-Security (HSTS)
Forces HTTPS connections, preventing downgrade attacks
Content-Security-Policy (CSP)
Controls allowed content sources, prevents XSS attacks
X-Frame-Options
Prevents clickjacking by blocking iframe embedding
X-Content-Type-Options
Prevents MIME-type sniffing vulnerabilities
Referrer-Policy
Controls how much referrer information is sent
Permissions-Policy
Controls browser features like geolocation, camera
Why Security Headers Matter
Without Proper Headers
- ✗XSS Attacks: Malicious scripts can run on your pages
- ✗Clickjacking: Your site can be embedded in malicious iframes
- ✗Downgrade Attacks: Users can be tricked into using HTTP
- ✗Data Leakage: Sensitive information exposed via referrers
With Lemwatch Monitoring
- Know exactly which headers are missing or misconfigured
- Get specific recommendations for each header
- Track your security grade improvement over time
- Include security status in client reports
How Security Header Monitoring Works
Automatic analysis and recommendations
Add Your Sites
Enter your URLs and Lemwatch immediately analyzes your security headers.
Automatic Analysis
We check all important security headers and grade your configuration.
Get Recommendations
Receive specific recommendations to improve your security posture.
Complete Security Monitoring
Everything you need to maintain a secure site
Security Header Analysis
Check for essential headers like HSTS, CSP, X-Frame-Options, and more.
HTTPS Configuration
Verify your site properly redirects to HTTPS and uses secure protocols.
Content Security Policy
Monitor your CSP headers to prevent XSS and injection attacks.
Security Alerts
Get notified when security headers are missing or misconfigured.
Security Reports
Include security scores in your professional reports for clients.
Server Configuration
Detect common server misconfigurations that expose vulnerabilities.
Security Headers FAQ
Common questions about security header monitoring
Start Securing Your Site Today
Join teams who use Lemwatch to monitor and improve their security posture. Security header monitoring included in all plans.
Quick answer
How do I monitor security headers like CSP and HSTS?
Read the response headers on every check, grade them against the current baseline, and alert when a header is weakened or disappears after a deploy.
- Headers graded: CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy
- Output: A letter grade from A to F with the missing headers listed
- Alerting: Fires when a previously present header is removed or weakened
- Free check: Public security header checker, no account needed