HTTP Header Analyzer.Every header, decoded.
Paste a URL and get every response header decoded and graded: caching directives interpreted the way CDNs and browsers actually interpret them, security headers checked against current best practice, compression negotiation verified, and a fix-first list ordered by impact.
HTTP Header Analyzer in four questions.
Cache-Control is the most misconfigured line on the web; the analyzer shows how edges and browsers will actually treat each directive combination.
CSP, HSTS, frame and content-type protections, present, absent, or present-but-wrong.
What was negotiated, what should have been, and what the difference costs in bytes.
One prioritized list, ordered by user-visible impact rather than alphabetical completeness.
How it works.
The same signals our analysts use in paid assessments, automated.
Fetches the URL and decodes the response exactly as delivered, including the intermediary fingerprints along the way.
CoreHeader combinations are evaluated the way real caches resolve them, including the conflicts and precedence rules that trip people up.
CoreGraded against present-day guidance, including the security-header baseline we apply in assessments.
CoreFindings come with concrete corrected header values you can paste into a config.
SupportingWhat you’ll get.
Every response header, explained in plain language.
IncludedCaching, security, compression and delivery each graded separately.
IncludedOrdered by impact, with corrected values ready to copy.
IncludedA stable link for the pull request or the ops channel.
IncludedWho it’s for.
The fastest way to find the caching mistake that’s tanking your hit ratio.
Verify the header baseline before the pen test finds it for you.
One paste per environment, staging surprises caught before production.
Cache and compression headers are the cheapest CWV wins available.
Free at launch. In build now.
The toolkit automates the detection and benchmark data behind the assessments we already run, the tools are how we prove the data is good.
Every tool ships free with shareable reports; the business model is the advisory behind it, not your email address.
First releases are in build. Dates are windows, not promises, we ship when the detection is trustworthy.
Want the answer before the tool exists? A free assessment runs the same analysis, human-graded, usually within 24 hours, and puts you on the early-access list for HTTP Header Analyzer.
HTTP Header Analyzer in context.
The research this tool automates.
HTTP Header Analyzer questions,
answered straight.
When does the analyzer launch?
It’s in development in the first toolkit wave, 2026 launch window; join the early-access list from the tools page.
Will it be free?
Yes, free with no signup, like every tool in the kit.
How is this different from viewing headers in DevTools?
DevTools shows you the headers; the analyzer tells you what they mean together: how caches will resolve conflicting directives, which security headers are absent, and what to change first, graded by the ruleset we use in paid assessments.
Does it check request headers too?
The first release focuses on responses, where nearly all of the fixable problems live; request-side analysis is on the roadmap.
Can it scan a whole site?
Launch scope is per-URL with shareable reports; crawling comes later.
I need an audit today.
A free assessment includes exactly this review, human-graded, usually within 24 hours.
All product names, logos and brands referenced in tool reports are the property of their respective owners and are used for identification purposes only. CDN World tools perform passive, non-intrusive analysis. Tool capabilities and launch timing described on this page are plans, not commitments, and may change.
