Chrome extension

HeaderSec support

Find help scanning the current website, restoring your latest result, completing verification, and using optional GitHub sign-in.

Getting started

  1. Open a public HTTP or HTTPS website in Chrome.
  2. Select the HeaderSec toolbar icon and confirm the origin shown in the popup.
  3. Choose Scan security headers.
  4. Review the score and priority findings, or open the full report for remediation details.

Sign-in is optional. If you sign in with GitHub, scans can be associated with your HeaderSec account. Anonymous scans remain available.

Troubleshooting

The popup says “Website unavailable”

Switch to a normal public http:// or https:// page. Chrome settings, extension pages, new-tab pages, local files, and private or internal network targets cannot be scanned.

Verification is required

Select Continue on site, complete the Cloudflare verification, and let HeaderSec continue with the same public origin. The extension never places the target's path or query in the request.

The scan failed or timed out

Confirm that the website is publicly reachable, wait a moment, and choose Try again. A target may also reject automated requests or respond too slowly for a safe scan.

The popup shows an older result

HeaderSec restores the latest locally saved result only for the same origin and labels it Last result. Choose Scan again to refresh it.

GitHub sign-in did not finish

Close the authorization window, reopen the popup, and try again. Ensure the current Web Store version is installed. You can continue scanning anonymously while sign-in is unavailable.

The full report is unavailable

Reopen the original website and scan it again. Reports use hard-to-guess URLs and may become unavailable after retention or operational cleanup.

What HeaderSec can access

After you open the popup, HeaderSec reads only the active tab URL and reduces it to its public origin. It does not read page content, cookies, passwords, form entries, URL paths, query parameters, or fragments. The scan is performed server-side against the website's public response.

Review the complete extension privacy policy.

Contact support

Email [email protected] with your Chrome version, the public origin you attempted to scan, the exact error message, and the approximate time it occurred.

Never send passwords, cookies, access tokens, private URLs, API keys, or other authentication information.