OpsRunr

Headers · 4 min read

Check security headers before you launch

Score CSP, HSTS, and frame protections as a hygiene check. It is not a pen test, but it is enough to catch embarrassing defaults.

Headers are free wins

Missing HSTS or clickjacking protections are common on rushed deploys. A scored header scan makes the gap visible before a client or marketplace review does.

Fix at your host or middleware, re-scan, and keep Domains + Uptime in the same workspace for the rest of site health.

Know the limit

A green header score is not a security guarantee. Still audit dependencies, auth, and secrets. Headers are hygiene, not a substitute for threat modeling.

Related checks

Try this on the health desk.

Sign up free, then choose Builder, Studio, or Agency from Billing when caps get tight.