INSTANT
Security header
& cookie checker.
Check your security headers, cookies and CORS.
See what’s missing. Know what to fix.
Layers of Insight
Security headers
CSP, HSTS, framing protection and more
Cookie flags
Secure, HttpOnly and SameSite attributes
CORS configuration
Origin reflection and credential handling
Transport & redirects
HTTPS and the path to your final response
UNDER THE HOOD
About Ceron Check
We make a small number of read-only requests to a public URL and inspect the responses. Nothing to install.
We inspect Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy. An enforced CSP frame-ancestors policy can replace X-Frame-Options. A missing header is a configuration gap, not proof of an exploitable vulnerability.
Only Set-Cookie headers returned during this unauthenticated request and its redirects. We check Secure, HttpOnly, SameSite and cookie prefix rules, while redacting values. We cannot see browser storage, script-created cookies or cookies that appear only after login. Cookie purpose affects the rating. Recognized preference, consent and analytics cookies can omit optional flags and are informational; sensitive-looking cookie names receive a context review. Some cookies intentionally need JavaScript access.
We send two additional GET requests to the final URL: one with an unrelated Origin and one with Origin: null. We report the observed access-control headers. A public wildcard policy may be intentional; wildcard plus credentials is rejected by browsers and is not reported as a proven data leak.
Low covers missing headers, optional hardening and cookie compatibility issues. Medium flags potentially sensitive cookie protections or credentialed CORS that need context. High requires stronger observed evidence, such as content served over HTTP without an HTTPS upgrade. Cookie names and platform hints are context, not proof of an exploit. Known Shopify preference and analytics cookies are informational. Critical is reserved for confirmed severe impact; this unauthenticated checker does not assign it from missing flags or headers. Results describe the response at the time of the check.
Scans are not saved by default. If you create a share link, Ceron stores only the redacted report and deletes it after 30 days. AI chat messages are sent for an answer but are not stored by Ceron. The target site and infrastructure providers may retain normal request logs. Avoid URLs containing secrets.
