What Security Headers Actually Do
Security headers tell browsers how to handle HTTPS, scripts, framing, referrers and browser features. Missing headers are evidence to review, not automatic proof that a site is unsafe.
Practical, evergreen explanations built around the questions administrators, security teams and technically curious users actually ask. Read the concept first, then use Scantide to inspect the evidence.
Security headers tell browsers how to handle HTTPS, scripts, framing, referrers and browser features. Missing headers are evidence to review, not automatic proof that a site is unsafe.
A Content-Security-Policy header can limit where scripts and other content are allowed to load from, reducing the impact of some injection attacks and making unexpected dependencies easier to spot.
HTTP Strict Transport Security tells a browser to prefer HTTPS for a site after receiving the policy, reducing opportunities for accidental HTTP use and some downgrade scenarios.
Cookie attributes influence when cookies are sent, whether browser scripts can read them, and how they behave across sites. They are small settings with important security and privacy consequences.
A page inherits part of the security and privacy posture of the scripts it loads. External analytics, widgets, consent platforms and libraries expand the trust chain beyond the site owner.
Trackers can support analytics, advertising, consent, fingerprinting, measurement and session replay. Their presence is not automatically malicious, but it changes who may receive data when a page is used.
A page may contact far more hosts than the address bar suggests. Network requests can expose analytics, APIs, CDNs, advertising, identity providers and other dependencies.
Forms and iframes can send users or data into systems operated by other domains. Reviewing their destinations helps explain where authentication, payment and embedded content actually live.
A risk score is useful as a shortcut, but the evidence behind it matters more. Different pages have different purposes, dependencies and acceptable exposure.
A browser can reveal headers, cookies, scripts, forms, frames and network behavior. It cannot see every server-side control, database setting or internal security decision.
Infrastructure country, provider and ASN context can help governance reviews, but location evidence should be treated as context rather than a complete legal conclusion.
Before entering a password, check the domain, HTTPS state, browser-visible dependencies, form destination and unexpected third-party content. The goal is context, not paranoia.
The guides explain the problem. Scantide Observe provides the corresponding viewpoint and evidence.
Explore Scantide ObserveAll Scantide guides