Pricing
$1.00 / 1,000 url scans
HTTP Security Headers Analyzer
Audit HTTP response headers (CSP, HSTS, X-Frame-Options) to verify web application security and compliance standards.
Pricing
$1.00 / 1,000 url scans
Rating
0.0
(0)
Developer
Actor stats
0
Bookmarked
2
Total users
1
Monthly active users
3 months ago
Last modified
Categories
Share
Security Headers Analyzer
Audit HTTP security headers against OWASP best practices across hundreds of URLs in a single run. Missing headers like HSTS, CSP, and X-Frame-Options are the most common findings in penetration tests โ yet most teams only discover them after an incident. Scan your entire domain inventory in minutes with automatic grading from A to F.
Features
- OWASP header checks โ validates HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, COOP, CORP, and COEP
- Automatic grading โ assigns a score (0-100) and letter grade (A-F) based on header coverage and configuration quality
- Actionable warnings โ flags weak configurations like
unsafe-inlinein CSP or missingmax-agein HSTS - Bulk processing โ scan hundreds of URLs concurrently in a single run
- Redirect-aware โ optionally follows redirects and reports the full redirect chain
- Flexible HTTP method โ use HEAD for speed or GET for servers that block HEAD requests
Input
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
urls | array | No | ["https://google.com"] | List of URLs to analyze for security headers |
url | string | No | โ | Single URL to analyze (use urls for bulk scanning) |
method | string | No | HEAD | HTTP method to use. HEAD is faster; switch to GET if a server blocks HEAD requests |
followRedirects | boolean | No | true | Whether to follow HTTP redirects before analyzing headers |
maxRedirects | integer | No | 5 | Maximum number of redirects to follow per URL (0-20) |
timeoutSeconds | integer | No | 15 | Request timeout per URL in seconds (1-120) |
concurrency | integer | No | 5 | Number of URLs to process in parallel (1-25) |
Input Example
{"urls":["https://google.com","https://github.com","https://example.com"],"method":"HEAD","followRedirects":true,"concurrency":10}
Output
Each URL produces one dataset record containing the security grade, score, list of missing and misconfigured headers, and all response headers for reference.
Key output fields:
inputUrl(string) โ the URL as submittedfinalUrl(string) โ the URL after redirects (if followed)status(number) โ HTTP status codegrade(string) โ letter grade from A (excellent) to F (critical gaps)score(number) โ numeric score from 0 to 100missing(array) โ list of required headers that are absentwarnings(array) โ list of configuration issues foundheaders(object) โ all response headers (lower-cased keys)redirects(array) โ redirect chain traversedcheckedAt(string) โ ISO 8601 timestamp
Output Example
{"inputUrl":"https://github.com","finalUrl":"https://github.com/","status":200,"grade":"B","score":80,"missing":["Referrer-Policy"],"warnings":["Missing Permissions-Policy.","Missing Cross-Origin-Opener-Policy (COOP).","Missing Cross-Origin-Resource-Policy (CORP).","Missing Cross-Origin-Embedder-Policy (COEP)."],"headers":{"strict-transport-security":"max-age=31536000; includeSubdomains; preload","content-security-policy":"default-src 'none'; base-uri 'self'; ...","x-frame-options":"deny","x-content-type-options":"nosniff"},"redirects":["https://github.com/"],"checkedAt":"2026-03-09T12:00:00.000Z"}
Pricing
| Event | Cost |
|---|---|
| URL Scan | $0.001 |
Pay only for URLs successfully scanned. Respects your per-run spending limit.
Use Cases
- Penetration test prep โ pre-scan client domains to identify missing security headers before a full engagement
- Compliance audits โ verify OWASP header requirements across all production endpoints for SOC 2 or ISO 27001
- DevOps CI/CD checks โ schedule regular scans to catch header regressions after deployments
- Agency security reports โ generate client-ready security grades for website portfolios
- M&A due diligence โ quickly assess the security posture of acquisition targets
Related Actors
| Actor | What it adds |
|---|---|
| SSL Cipher Checker | Audit TLS cipher suites and protocol versions alongside header analysis |
| SSL Certificate Monitor | Monitor certificate expiry dates to complement header-level security checks |
| Tech Stack Analyzer | Identify the CMS, frameworks, and CDNs behind each scanned URL |
