Run this check →

New accounts start with 40 free credits.

Check security headers and TLS configuration against OWASP

Security Headers & Transport — OWASP

Last updated: 29 September 2026

WHAT IT CHECKS

Server configuration, response-header configuration and deployment documentation, against 63 rules — HSTS, Content-Security-Policy, clickjacking protection, MIME-sniffing, CORS, cookie attributes, caching of sensitive responses, the Cross-Origin isolation policies, version-disclosing headers, TLS versions and cipher suites, certificate signature algorithms, and HTTP-to-HTTPS redirects.

WHERE THE RULES COME FROM

The OWASP Cheat Sheet Series.

WHAT IT DOES NOT CHECK

  • Referrer-Policy is not covered, and is listed on every report. The pack covers 17 of its 18 topics.
  • Configuration, not a live scan. It reads the configuration you give it; it does not probe your server.

WHAT YOU GET BACK

  • Each gap it finds, with the rule it fails and the source text that rule was taken from, quoted, so you can check it yourself.
  • Replacement wording for each finding, and a corrected copy of your document to download.
  • The pack's declared gaps, printed on every report, so you know what was not checked.

HOW TO RUN IT

In the browser. Sign in at https://vera.ink/verify, paste or upload the document, and choose this pack. New accounts start with 40 credits; a check costs 3 credits up to about 4,500 words.

From your AI assistant. vera.ink is an MCP server. Connect it to Claude Code or Cursor and ask your assistant to check a file against this pack: https://vera.ink/developers

GOOD TO KNOW

  • vera.ink only reports findings it can tie to a rule in this pack, and quotes the source text so you can check it. Anything it can't tie to a rule is dropped from the report.
  • It is a review aid, not legal advice or a certification. Read each finding before you act on it.

More checks: https://vera.ink/check