HTTP Methods Checker

See which HTTP methods a URL allows, and whether risky ones like TRACE are enabled.


HTTP Methods Checker

Web servers can accept more than GET and POST. Methods like PUT and DELETE change content, and TRACE can help attackers read cookies (cross-site tracing). This checker sends only harmless requests (GET, HEAD, OPTIONS and TRACE), reads the Allow and CORS headers, and tells you if TRACE is enabled or risky methods are advertised. It never sends PUT, DELETE or other methods that change data.

How to use HTTP Methods Checker

  1. Enter the URL, such as your homepage or an API endpoint.
  2. Click Check methods.
  3. Review the findings and the table of responses.

When it comes in handy

  • Following up a penetration test or security scan finding.
  • Checking that an API only exposes the methods it should.
  • Confirming TRACE is disabled on your web server.

Frequently asked questions

How do I disable TRACE?
In Apache add "TraceEnable off" to the main config. nginx rejects TRACE by default (405). On IIS use request filtering. Many CDNs and firewalls also block it.
Why does OPTIONS return 405 or 404?
Many sites simply do not answer OPTIONS unless they serve an API with CORS. That is fine.

Choose which cookies SEOpeck may use. You can change this at any time from "Cookie settings" at the bottom of every page.