http-security-headers-mcp
by shakiltousif
README.md
# http-security-headers-mcp
Analyze and score HTTP security headers (CSP, HSTS, CORS, cookies) with actionable fix recommendations for web applications.
[](https://mcpize.com/servers/http-security-headers-mcp)
## Tools
| Tool | Description |
|------|-------------|
| `scan_headers` | Fetch a URL and analyze all security headers. Returns A+ to F grade with findings. |
| `score_headers` | Score a set of headers you provide. Returns grade and per-header breakdown. |
| `analyze_csp` | Deep analysis of a Content-Security-Policy header. Detects unsafe sources and bypass risks. |
| `generate_headers` | Generate recommended security headers config for Express, Next.js, nginx, Apache, Cloudflare, or Vercel. |
## Quick Start
### Install from MCPize (Recommended)
```bash
npx -y mcpize connect @shakiltousif/http-security-headers-mcp --client claude
```
Or visit: [mcpize.com/mcp/http-security-headers-mcp](https://mcpize.com/mcp/http-security-headers-mcp)
### Per-client install
```
Claude: claude mcp add --transport http http-security-headers-mcp https://http-security-headers-mcp.mcpize.run/mcp
Cursor: cursor mcp add http-security-headers-mcp https://http-security-headers-mcp.mcpize.run/mcp
Windsurf: windsurf mcp add http-security-headers-mcp https://http-security-headers-mcp.mcpize.run/mcp
```
### JSON Config (manual setup)
```json
{
"mcpServers": {
"http-security-headers-mcp": {
"url": "https://http-security-headers-mcp.mcpize.run/mcp"
}
}
}
```
### Run Locally
```bash
npm install
mcpize dev # Start dev server with hot reload
mcpize dev --playground # Interactive testing in your browser
```
Server runs at `http://localhost:3000/mcp`
## Development
```bash
mcpize dev # Development mode (port 3000, hot reload, loads .env)
npm run build # Compile TypeScript
npm test # Run unit tests (26 tests)
bash test-mcp.sh # MCP protocol smoke test (14 checks)
npm start # Run compiled server (port 8080)
```
## Deploy
```bash
mcpize login # Authenticate (opens browser)
mcpize deploy # Ship it!
```
## Project Structure
```
src/
index.ts # Express + MCP server setup, tool registration
tools.ts # Pure business logic (header analysis, scoring, CSP parsing)
tests/
tools.test.ts # Unit tests (vitest)
test-mcp.sh # MCP protocol smoke test
mcpize.yaml # MCPize deployment config
Dockerfile # Production container build
```
## License
MIT
This server cannot be deployed
Maintenance
ActivityInactive
ResponsivenessNo issues