The checker reuses the HTTP header parser to normalize names and detect duplicate header names.
Security header names are matched case-insensitively and grouped into transport, content and framing, privacy and permissions, and cross-origin isolation sections.
HSTS max-age is parsed as seconds and compared with a one-year threshold.
Frame protection accepts either X-Frame-Options DENY or SAMEORIGIN, or a CSP frame-ancestors directive.
Findings are conservative hints. Missing COOP, CORP, and COEP are not treated as high risk because isolation requirements depend on the application.