Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.
In this guide
- Key takeaways
- What does Snyk's Security Headers test check?
- How is the grade calculated?
- Why do the specific headers matter?
- How to run the Snyk Security Headers test?
- How should you interpret the detailed feedback?
- What are concrete steps to fix common failures?
- When should you go beyond the Snyk test?
- What is the overall takeaway?
Key takeaways
- Snyk's free Security Headers test checks for the presence and correct values of the most common security headers.
- The test assigns a letter grade (A - F) based on how many required headers are present and properly configured.
- Use the test results to prioritize fixing missing or mis - configured headers like CSP, HSTS, X - Content - Type - Options, X - Frame - Options, Referrer - Policy, and Permissions - Policy.
What does Snyk's Security Headers test check?
Snyk's test examines the HTTP response headers returned by a site and looks for eight widely used security headers. It evaluates each header against best - practice values and marks missing or insecure settings as lower grades.
How is the grade calculated?
Snyk assigns a letter grade from A to F based on the proportion of required headers that are present and correctly configured. A site with all eight headers set to recommended values receives an A, while missing or insecure headers lower the grade.
Why do the specific headers matter?
Each header provides a distinct protection: CSP blocks unsafe scripts, HSTS forces HTTPS, X - Content - Type - Options stops MIME sniffing, X - Frame - Options prevents clickjacking, Referrer - Policy limits referrer leakage, and Permissions - Policy restricts powerful browser features.
How to run the Snyk Security Headers test?
- Visit the Snyk Security Headers testing page.
- Enter the full URL of the site you want to assess (including
https://). - Click the Test button.
- Wait about a second for Snyk to fetch the page and evaluate the response headers.
- Review the resulting grade and detailed per - header feedback.
How should you interpret the detailed feedback?
Snyk lists each checked header with a status: Pass means the header is present and follows recommended configuration; Warn means the header is present but uses a non - optimal value; Fail means the header is missing or set to a value that defeats its purpose. Focus first on any Fail items, then address Warn items.
What are concrete steps to fix common failures?
| Header | Typical failure | Fix example |
|---|---|---|
| CSP | Missing or includes 'unsafe-inline' | Content-Security-Policy: default-src 'self'; script-src 'self' https://apis.example.com; object-src 'none'; |
| HSTS | Not set or missing includeSubDomains | Strict-Transport-Security: max-age=31536000; includeSubDomains; preload |
| X-Content-Type-Options | Missing | X-Content-Type-Options: nosniff |
| X-Frame-Options | Missing or set to ALLOWALL | X-Frame-Options: SAMEORIGIN |
| Referrer-Policy | Missing or set to no-referrer-when-downgrade | Referrer-Policy: strict-origin-when-cross-origin |
| Permissions-Policy | Missing or too permissive | Permissions-Policy: geolocation=(), camera=(), microphone=() |
When should you go beyond the Snyk test?
You should add broader scanning once you need assurance about TLS configuration, JavaScript vulnerabilities, and third - party risks. Decloak’s free scan runs in about 15 seconds, checks HTTP/TLS posture, static HTML, rendered - page network behavior, JavaScript CVE libraries, tag manager settings, third - party domain mapping, vibe - coded platform security, and provides an AI - written executive summary. For deeper coverage, paid tiers add DNS analysis, subdomain discovery, and active security testing.
What is the overall takeaway?
Snyk’s free Security Headers test gives a quick, graded view of header configuration, but combining it with Decloak’s multi - layer scanning gives a more complete picture of web security, including TLS settings and platform - specific misconfigurations.
Related guides
How to Fix a Missing Content - Security - Policy Header
Learn concrete steps to add, test, and harden a Content - Security - Policy header, from server configuration to iterative reporting and verification.
Is HTTP 1.1 a security risk?
HTTP 1.1 is not a direct vulnerability, but its plain - text design and parsing ambiguities can create attack surfaces that need mitigation, especially when not used over TLS.
Is JavaScript a security risk?
JavaScript can be a major attack surface because injected scripts run with the same privileges as the page, but proper sanitization, CSP, and safe frameworks eliminate most risks.