HTTP Security

Review HTTP security headers across your public assets.

Splorix summarizes recommended HTTP security headers for authorized domains and subdomains, including HSTS, CSP, framing controls, MIME sniffing protection, referrer and permissions policies, Cross-Origin isolation headers, and raw evidence.

Header presence

See whether recommended HTTP security headers are present or missing for the selected host.

Per-header guidance

Open explanations for each header so teams understand what the control does and why it matters.

Refreshable snapshots

Refresh HTTP Security after CDN, reverse-proxy, or application header changes.

Raw evidence

Open, expand, and copy the stored HTTP Security JSON payload for tickets and technical review.

What is HTTP Security intelligence?

A defensive header view for the hosts you monitor.

HTTP Security intelligence gives teams a structured view of the defensive headers exposed by public web assets. Splorix summarizes whether headers such as HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and Cross-Origin policies are present, stores a refreshable snapshot, and keeps the raw provider payload for evidence.

Why it matters

Missing security headers leave common browser attack paths open.

HTTP security headers sit between users, browsers, CDNs, and application responses. When they are missing or incomplete, sites are more exposed to protocol downgrade, XSS impact, clickjacking, MIME confusion, and unnecessary browser capabilities. Splorix makes those gaps visible next to the rest of your attack surface context.

Transport trust

HSTS helps enforce HTTPS and reduce protocol downgrade and man-in-the-middle risk once HTTPS is correctly deployed.

XSS and injection resistance

Content Security Policy constrains which scripts and resources a page may load, reducing the blast radius of XSS and data injection.

Clickjacking controls

X-Frame-Options and related framing policies help stop hostile sites from embedding your UI for clickjacking attacks.

Evidence for owners

Clear Yes/No signals and raw JSON make it easier to hand remediation work to platform, CDN, or application owners.

How it works

From HTTP Security snapshot to reviewable Yes/No signals.

01

Select a monitored host

HTTP Security follows the selected domain or subdomain in the workspace, so teams review headers for the exact public host they care about.

02

Fetch header intelligence

Splorix uses HTTP Security intelligence to check recommended headers and stores the response as a refreshable snapshot.

03

Summarize presence

The snapshot is mapped into readable Yes/No rows for HSTS, CSP, framing, MIME sniffing, referrer, permissions, and Cross-Origin policies.

04

Highlight missing controls

Missing headers become actionable signals so gaps do not hide in raw response data.

05

Refresh when needed

Users can refresh after header deployments, CDN rule changes, reverse-proxy updates, or investigation work.

06

Inspect and copy raw JSON

The raw HTTP Security payload can be opened, expanded, and copied for debugging, evidence sharing, or deeper technical review.

Review signals

Know which headers to inspect before attackers find the gaps.

The HTTP Security block turns provider output into practical review fields. Teams can quickly see which headers are present, which are missing, and which controls deserve remediation first.

Content Security Policy

CSP constrains which resources a page may load and is one of the strongest browser-side XSS mitigations when configured carefully.

Strict Transport Policy

HSTS tells browsers to use HTTPS only, reducing accidental HTTP exposure and protocol downgrade attempts.

X-Content-Type-Options

nosniff stops browsers from MIME-sniffing responses away from the declared content type.

X-Frame-Options

Framing controls help protect users from clickjacking by limiting whether the page may be embedded.

Referrer and Permissions policies

These headers reduce sensitive URL leakage and disable powerful browser features the application does not need.

Cross-Origin policies

COOP, CORP, and COEP help isolate browsing contexts and control how cross-origin resources interact with the page.

Security actions

Turn header visibility into remediation and ownership work.

Prioritize missing high-value headers

Start with HSTS, CSP, X-Content-Type-Options, and framing controls when the snapshot shows broad gaps.

Fix at the right layer

Apply headers on the origin, reverse proxy, load balancer, or CDN depending on where responses are finalized.

Validate carefully

CSP and Cross-Origin policies can break legitimate scripts and embeds, so roll out with testing and staged environments.

Use raw payload as evidence

Copy raw HTTP Security evidence when opening tickets or comparing provider output with live curl checks.

Coordinate ownership

Header remediation often involves frontend, platform, CDN, and security teams, so ownership should be explicit.

Retest after deployment

Refresh the HTTP Security snapshot after changes to confirm the public host now exposes the expected headers.

FAQ

HTTP Security questions.

Short answers for teams that want to monitor defensive HTTP headers inside their external attack surface workflow.

What does Splorix HTTP Security review?

Splorix reviews recommended HTTP security headers for an authorized domain or subdomain, including Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options, X-XSS-Protection, Referrer-Policy, Permissions-Policy, and Cross-Origin policies, plus raw evidence.

What do Yes and No mean in the HTTP Security block?

Yes means the header was detected as present on the host response. No means the recommended header was missing from the latest snapshot.

Can I refresh HTTP Security data?

Yes. Users can refresh the HTTP Security snapshot for the selected domain or subdomain after header changes, CDN updates, or investigation work.

Does Splorix auto-fetch HTTP Security when a domain is added?

Yes. When HTTP Security data is unknown, Splorix can fetch it on first dashboard load or when a new domain is added, then keep a refreshable snapshot.

What is the raw HTTP Security JSON payload for?

The raw payload is stored evidence from the provider response. It helps teams debug header behavior, share proof with platform owners, and compare details beyond the Yes/No summary.

Is the dashboard HTTP Security block the same as the free HTTP Security tool?

The free HTTP Security tool is a standalone public lookup with a daily quota. Workspace HTTP Security is tied to authorized domains and subdomains, refreshable snapshots, findings, and broader attack surface context.

Who should use HTTP Security intelligence?

Security teams, platform engineers, frontend owners, SaaS operators, and compliance teams can use HTTP Security intelligence to review defensive headers and prioritize remediation.

Header visibility

Review HTTP security headers before gaps become findings.

Use Splorix to connect HTTP Security intelligence with domains, subdomains, scans, endpoints, and security context in one workspace.