http_headers_audit
Fetch a URL and evaluate security headers like HSTS, CSP, and cookie flags, scoring policy quality rather than mere presence. Identify misconfigurations without retrieving the body.
Instructions
Fetch a URL in scope and evaluate its security headers (HSTS, CSP, X-Content-Type-Options, Referrer-Policy, CORS, cookie flags), scoring the QUALITY of each policy rather than its mere presence. The body is not retrieved. Does NOT test exploitability. Cost: 1 quota unit.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| url | Yes | Absolute http(s) URL in scope. | |
| follow_redirects | No | Follow in-scope redirects before auditing. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| url | Yes | ||
| grade | No | ||
| score | No | ||
| status | Yes | ||
| findings | No | ||
| pinned_ip | No | ||
| missing_headers | No | ||
| present_headers | No |