An MCP server that gives Claude and other AI agents the ability to audit any public URL's HTTP security headers.
What it checks:
* HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy
* HTTPS enforcement and redirect chain depth
* Presence of security.txt, robots.txt, sitemap.xml
Payment model:
* 0.05 USDC per scan, paid automatically on Base via the x402 proto
Enables deep security auditing of web applications directly from AI IDEs including Cursor and Claude Code. Scans URLs for vulnerabilities, returns security scores with SHIP/BLOCK verdicts, and provides specific fix prompts for remediation.
Enables users to analyze HTTP response headers of any URL for security and configuration, returning a 0-100 security score, HSTS/CSP and header checks, server detection, caching details, and recommendations. Supports pay-per-call access via x402 micropayments.