Transport trust
HSTS helps enforce HTTPS and reduce protocol downgrade and man-in-the-middle risk once HTTPS is correctly deployed.
HTTP Security
Splorix summarizes recommended HTTP security headers for authorized domains and subdomains, including HSTS, CSP, framing controls, MIME sniffing protection, referrer and permissions policies, Cross-Origin isolation headers, and raw evidence.
See whether recommended HTTP security headers are present or missing for the selected host.
Open explanations for each header so teams understand what the control does and why it matters.
Refresh HTTP Security after CDN, reverse-proxy, or application header changes.
Open, expand, and copy the stored HTTP Security JSON payload for tickets and technical review.
What is HTTP Security intelligence?
HTTP Security intelligence gives teams a structured view of the defensive headers exposed by public web assets. Splorix summarizes whether headers such as HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and Cross-Origin policies are present, stores a refreshable snapshot, and keeps the raw provider payload for evidence.
Why it matters
HTTP security headers sit between users, browsers, CDNs, and application responses. When they are missing or incomplete, sites are more exposed to protocol downgrade, XSS impact, clickjacking, MIME confusion, and unnecessary browser capabilities. Splorix makes those gaps visible next to the rest of your attack surface context.
HSTS helps enforce HTTPS and reduce protocol downgrade and man-in-the-middle risk once HTTPS is correctly deployed.
Content Security Policy constrains which scripts and resources a page may load, reducing the blast radius of XSS and data injection.
X-Frame-Options and related framing policies help stop hostile sites from embedding your UI for clickjacking attacks.
Clear Yes/No signals and raw JSON make it easier to hand remediation work to platform, CDN, or application owners.
How it works
HTTP Security follows the selected domain or subdomain in the workspace, so teams review headers for the exact public host they care about.
Splorix uses HTTP Security intelligence to check recommended headers and stores the response as a refreshable snapshot.
The snapshot is mapped into readable Yes/No rows for HSTS, CSP, framing, MIME sniffing, referrer, permissions, and Cross-Origin policies.
Missing headers become actionable signals so gaps do not hide in raw response data.
Users can refresh after header deployments, CDN rule changes, reverse-proxy updates, or investigation work.
The raw HTTP Security payload can be opened, expanded, and copied for debugging, evidence sharing, or deeper technical review.
Review signals
The HTTP Security block turns provider output into practical review fields. Teams can quickly see which headers are present, which are missing, and which controls deserve remediation first.
CSP constrains which resources a page may load and is one of the strongest browser-side XSS mitigations when configured carefully.
HSTS tells browsers to use HTTPS only, reducing accidental HTTP exposure and protocol downgrade attempts.
nosniff stops browsers from MIME-sniffing responses away from the declared content type.
Framing controls help protect users from clickjacking by limiting whether the page may be embedded.
These headers reduce sensitive URL leakage and disable powerful browser features the application does not need.
COOP, CORP, and COEP help isolate browsing contexts and control how cross-origin resources interact with the page.
Security actions
Start with HSTS, CSP, X-Content-Type-Options, and framing controls when the snapshot shows broad gaps.
Apply headers on the origin, reverse proxy, load balancer, or CDN depending on where responses are finalized.
CSP and Cross-Origin policies can break legitimate scripts and embeds, so roll out with testing and staged environments.
Copy raw HTTP Security evidence when opening tickets or comparing provider output with live curl checks.
Header remediation often involves frontend, platform, CDN, and security teams, so ownership should be explicit.
Refresh the HTTP Security snapshot after changes to confirm the public host now exposes the expected headers.
FAQ
Short answers for teams that want to monitor defensive HTTP headers inside their external attack surface workflow.
Splorix reviews recommended HTTP security headers for an authorized domain or subdomain, including Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options, X-XSS-Protection, Referrer-Policy, Permissions-Policy, and Cross-Origin policies, plus raw evidence.
Yes means the header was detected as present on the host response. No means the recommended header was missing from the latest snapshot.
Yes. Users can refresh the HTTP Security snapshot for the selected domain or subdomain after header changes, CDN updates, or investigation work.
Yes. When HTTP Security data is unknown, Splorix can fetch it on first dashboard load or when a new domain is added, then keep a refreshable snapshot.
The raw payload is stored evidence from the provider response. It helps teams debug header behavior, share proof with platform owners, and compare details beyond the Yes/No summary.
The free HTTP Security tool is a standalone public lookup with a daily quota. Workspace HTTP Security is tied to authorized domains and subdomains, refreshable snapshots, findings, and broader attack surface context.
Security teams, platform engineers, frontend owners, SaaS operators, and compliance teams can use HTTP Security intelligence to review defensive headers and prioritize remediation.
Header visibility
Use Splorix to connect HTTP Security intelligence with domains, subdomains, scans, endpoints, and security context in one workspace.