HTTP Security Header Checker - Online HSTS, CSP, X-Frame Analysis
Paste response headers string and get a security audit. Check presence and configuration of key security headers. Local analysis.
UD5 Toolkit
Instantly analyze HTTP response headers of any URL to detect potential browser extension injected scripts or suspicious modifications.
| Header Name | Value |
|---|
X-Chrome-Extension, X-Firefox-Extension, or custom X-* headers added by privacy tools, ad blockers, or shopping assistants may indicate extension activity. We also flag unusual CSP directives that allow extension resources.Paste response headers string and get a security audit. Check presence and configuration of key security headers. Local analysis.
Browse Unicode by block: Latin, Cyrillic, CJK, Emoticons. See characters and copy with a click. Full reference.
Paste a user agent string to get a human-readable breakdown of browser, operating system, and device. See your own current agent info automatically.
Test if a script or style will be allowed by a given CSP. Compute hash/nonce. Strengthen your site’s defense against XSS. Local.
Build an iframe with different sandbox flags and see live which features are blocked. For secure embedding.
Enter a URL and see the full redirect chain with status codes and response times. Also validates against your chosen rule.
Paste a potential XSS vector and see if it executes in a sandboxed iframe. For security researchers and education.
Paste an HTML snippet and see how a screen reader might interpret it. Highlights missing alt texts and ARIA misuses. Educational.
Paste a JSON Web Token and decode its header and payload. Verify signature if you provide the secret. Fully local.
Paste a robots.txt file and validate its syntax. See if a specific user‑agent can access a path. Essential for webmasters.
Design a clean, professional email signature with your photo, links, and disclaimers. Copy the HTML to use in Gmail/Outlook.
Compose messages with bold, italic, links, and code. See the raw HTML or Markdown for your Telegram bot API calls.
Create a polished HTML email signature with your photo, links, and company details. Live preview and copy HTML to clipboard. Works with Gmail, Outlook, Apple Mail.
See your monitor's color depth and pixel depth. Detect if HDR or wide gamut is available using media queries.
Compare two text blocks and highlight differences line by line. Ideal for code review and document revisions. All diffs computed locally for privacy.
Parse a URL's query string into a key-value table, or build a query string from parameters. Perfect for API testing and web development.
Type your name and create a stylized ASCII text banner for email signatures or forum posts. Choose a font style.
Paste a website's HTML and see which text is only visible to screen readers (e.g., .sr‑only). Preview the accessible layer.
Enter HTML with aria-labels and see what a screen reader would announce. Simulates common patterns. Local educational tool.
Test required, pattern, minlength etc. See validity states and custom error messages. Learn browser‑native validation.
Paste two JSON objects and find the structural differences with side‑by‑side highlighted output. Indispensable for API debugging.
Design borders with linear or conic gradients. Supports border‑image and background‑clip methods. Copy optimized CSS.
Create custom traceable handwriting worksheets with name or sentence. Print in dotted font. Great for teachers and parents.
Simulate a traceroute by entering a destination IP. Learn about AS paths and latency. Does not send real packets; educational visualisation.
Graph a cubic‑bezier or steps easing function and see a bouncing ball animation using it. Copy the CSS timing‑function.
Draw pixel art with a grid, color palette, and eraser. Export as PNG. Perfect for game developers and hobbyists.
Draw walls on a grid and watch A*, Dijkstra, or BFS find the shortest path. Interactive animation. Learn graph traversal.
Check if the browser has captured the beforeinstallprompt event. Understand why your PWA is (or isn't) installable.
Paste your CSS and see warnings for properties that have limited browser support. Links to CanIUse. Modernize safely.
Check if a password appears in the Have I Been Pwned database using k‑Anonymity. Only the first 5 characters of the hash are sent.