Header Peek by Scrap Labs
Right-click any page and Header Peek reports the security headers a server actually sent: HSTS, CSP, X-Frame-Options, XCTO, Referrer-Policy and Permissions-Policy, in one notification. From the team behind Hackedself.
Extension Metadata
About this extension
Header Peek answers a simple question about any page you are on: which of the headers that matter did the server bother to send? Right-click the page or any link and choose Peek at the response headers. The add-on fetches the URL fresh, reads the response, and pops a notification listing six headers that harden a site: Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy. Each shows the first value it sent; the ones that never arrived are called out as missing, so a missing header is a finding, not a mystery. Results are kept only for the last check on the device. Built by Scrap Labs, the team behind Hackedself, a publication about biohacking protocols, supplement evidence and the security hygiene of the tools a self-experimenter runs.
Rated 0 by 0 reviewers
Permissions and data
Required permissions:
- Display notifications to you
- Access your data for all websites
Data collection:
- The developer says this extension doesn't require data collection.
More information
- Add-on Links
- Version
- 1.0.0
- Size
- 8.63 KB
- Last updated
- 4 days ago (Sep 24, 2026)
- Related Categories
- License
- MIT License
- Version History
- Add to collection