HeaderGuard
Server Details
Scan a website's HTTP security headers (HSTS, CSP, framing, COOP/CORP, cookies). Score + fixes.
- Status
- Healthy
- Last Tested
- Transport
- Streamable HTTP · MCP 2025-11-25
- URL
TDQS
Score is being calculated.
Available Tools
1 toolscan_headersScan a website's HTTP security headers (HSTS, CSP, framing, COOP/CORP/COEP, cookies)Read-onlyIdempotentInspect
Scan the HTTP security headers of a public website. Returns a 0–100 score and A+–F grade (HTTPS 10, HSTS 15, CSP 25, framing 10, X-Content-Type-Options 10, Referrer-Policy 10, Permissions-Policy 5, COOP 5, CORP 5, cookies 5, minus up to 5 for version-leak headers; without HTTPS the score is capped at 39), each header's status and notes, recommended fix headers, and a link to the full report with copy-paste snippets for nginx, Apache, Cloudflare, Netlify, Vercel and Express. Read-only: it sends ordinary GET requests to the site (following up to 10 redirects, each safety-checked) and never reads page bodies. Same engine and scoring as the HeaderGuard JSON API (GET /api/scan).
| Name | Required | Description | Default |
|---|---|---|---|
| url | Yes | URL or bare domain to scan, e.g. example.com or https://example.com/login. A bare domain is scanned as https://<domain>/ (plain HTTP if HTTPS does not answer). | |
| include_raw | No | Also return the full /api/scan JSON (redirect chain, all response headers with cookie values redacted, per-platform fix snippets) in structuredContent.raw. Larger output. |
Output Schema
| Name | Required | Description |
|---|---|---|
| raw | No | Full /api/scan response (only when include_raw is true) |
| url | Yes | Normalized URL that was scanned |
| plan | Yes | |
| fixes | Yes | |
| grade | No | Omitted when the grade is withheld |
| notes | No | |
| score | No | Omitted when the grade is withheld |
| apiUrl | No | |
| cached | No | |
| version | No | |
| finalUrl | Yes | |
| findings | Yes | |
| reportUrl | Yes | |
| scannedAt | No | |
| finalStatus | No | |
| reliability | Yes | |
| gradeWithheld | Yes | true when the site blocked, rate-limited or challenged the scanner |
| redirectCount | No | |
| gradeWithheldReason | No |
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
1 tool update
- First observed
scan_headers
Related MCP Connectors
Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes
Check a deployed web app for security headers, SEO, accessibility and performance, with a grade.
MDN HTTP Observatory — grade any website's HTTP security headers and get the specific fixes, from…
Scan a web page for accessibility, security, privacy, quality and SEO issues, with fixes.
Related MCP Servers
- FlicenseNot gradedqualityDmaintenanceAnalyze and score HTTP security headers (CSP, HSTS, CORS, cookies) with actionable fix recommendations for web applications.-
- AlicenseAqualityCmaintenanceEnables Claude to scan a website's HTTP security headers and receive an A–F grade against OWASP best practices, including per-header pass/warn/fail results and copy-paste fixes for missing headers.1MIT
- AlicenseNot gradedqualityCmaintenanceEnables scanning any website's HTTP security headers to obtain Mozilla Observatory grades, detailed pass/fail test results with remediation guidance, and grade distribution context.75 npmMIT
- AlicenseNot gradedqualityBmaintenanceEnables AI agents to audit URLs for security headers, generate CSP Level 3 policies, compute SRI hashes, evaluate WCAG 2.2 contrast, and remediate headers.MIT
Glama MCP Gateway
Add one secure layer between your agents and this server.