Security Headers Grader — one row per domain
Pricing
$1.00 / 1,000 row returneds
Security Headers Grader — one row per domain
Grades the security headers of every domain in a list: HSTS, CSP, X-Frame-Options and more, plus TLS. No browser needed, so it runs fast and cheap over large lists.
Pricing
$1.00 / 1,000 row returneds
Rating
0.0
(0)
Developer
The Artifact Machine
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
2 days ago
Last modified
Categories
Share
Grades the security headers of every domain in a list: HSTS, CSP, X-Frame-Options and more, plus TLS. No browser needed, so it runs fast and cheap over large lists.
Grade a whole list for the headers a security review will ask about.
What you get
One row per domain, with these columns:
headerScoresslScoremissingHeadershasHstshasCspgrade
Real output
Measured on https://www.hubspot.com/:
{"headerScore": 54,"sslScore": 80,"missingHeaders": ["Permissions-Policy"],"hasHsts": true,"hasCsp": true,"grade": "D"}
Input
Give it a list of domains:
{ "domains": ["example.com", "another.com"] }
Or chain it after any actor that produces a list — Google Maps Scraper, a CRM
export, a prospect list — by passing that dataset as items and naming the
column that holds the website:
{ "items": [{ "title": "Acme", "website": "acme.com" }], "field": "website" }
Domains it could not read
A domain that blocks the scan, times out, or errors comes back with
measured: false, a reason, and every data column null — never a zero
and never a false.
That matters at bulk. One fabricated false in a sheet of ten thousand rows
is worse than a missing row, because nobody audits the row that looks
plausible. Filter on measured and you know exactly what you are looking at.
Roughly one site in eight refuses an automated reader, and this actor uses plain HTTP rather than a browser, so its share is higher.
Notes
- Reads the homepage only, one page per domain.
- No browser — plain HTTP requests, so it runs fast and cheap over large lists.