Security Headers Checker: Website Audit for CSP & HSTS avatar

Security Headers Checker: Website Audit for CSP & HSTS

Pricing

from $1.40 / 1,000 site auditeds

Go to Apify Store
Security Headers Checker: Website Audit for CSP & HSTS

Security Headers Checker: Website Audit for CSP & HSTS

Bulk-check website security headers: CSP, HSTS, framing, cookies, HTTPS redirect, security.txt, with a grade per site and evidence for each finding. Bench: 21/21 policy checks vs 19/21, at $2 per 1,000 sites.

Pricing

from $1.40 / 1,000 site auditeds

Rating

0.0

(0)

Developer

hiver

hiver

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

a day ago

Last modified

Categories

Share

Grade a list of websites on public security hygiene in one run. Use it to prioritise outreach for a security or web-agency service ("your site has no CSP and no HSTS"), to check your own sites or a client portfolio, or to add a hygiene score to vendor and prospect research.

$2 per 1,000 sites audited; sites that do not respond are free.

Unofficial. Not affiliated with, endorsed by or sponsored by any company or website named in the results.

Measured against two other security-header Actors

Our board's Lab bench gives this Actor and two other security-header Actors on the Apify Store the same 8 sites in three jobs, then checks the answers against hand-verified facts (2026-10-08, build 0.1.5):

This Actorpsx/security-headers-tls-auditninhothedev/security-headers-checker
Plain vs hardened sites (HSTS, HTTPS redirect, findings)5 of 5 checks5 of 52 of 5
CSP and HSTS policy correctness (weak max-age, unsafe-inline, ignored unsafe-inline under nonce/strict-dynamic, base-uri, subdomain coverage, cookies)11 of 119 of 113 of 11
Sites behind bot protection5 of 55 of 53 of 5
All checks matched21 of 21 (100%)19 of 21 (90%)8 of 21 (38%)
Fields filled100%100%71%
Price per 1,000 sites in these runs, free plan$2.02$9.88$1.02

Same coverage as psx at about a fifth of its price, and the only one of the three that got every policy check right. Three jobs and 8 sites are a small sample; the bench runs again after every new build.

What you get

One row per site:

  • grade (A to F) and score (0-100) from a transparent checklist
  • issues: plain-language list of what is missing or weak
  • headers: Strict-Transport-Security, Content-Security-Policy, X-Frame-Options or CSP frame-ancestors, X-Content-Type-Options, Referrer-Policy, Permissions-Policy. Entries retain value, present, usable and detail. usable is checklist effectiveness, not a guarantee of a safe policy.
  • policyAnalysis.csp: parsed directives, effective script element/event-handler/eval sources, nonce/hash and strict-dynamic handling, duplicate-directive first-wins behavior, fetch fallback and the intersection of enforcing policies. allowsUnsafeInline means arbitrary inline script elements are permitted after these checks, not merely that the keyword exists. Report-only policies are shown separately and do not protect.
  • policyAnalysis.framing: enforcing CSP frame-ancestors overrides X-Frame-Options, including a broad wildcard that makes XFO DENY ineffective. Neither frame-ancestors nor base-uri inherits default-src.
  • policyAnalysis.hsts: parsed max-age, includeSubDomains and preload; flags missing subdomain coverage and a max-age below the optional one-year preload minimum. preloadHeaderEligible checks only the header, not the preload list, certificates or subdomain HTTPS. Preloading is opt-in, not mandatory.
  • findings: stable code, severity (info, low, medium, high), message and evidence: {header, value} containing the exact observed header field. Missing headers have null evidence. CSP findings identify their policy/directive; an identified weakness mitigated by another enforcing policy is informational. Wildcards and HTTP sources are configuration review findings, not proof of exploitable resource loading.
  • httpProbe: plain-HTTP final URL, status and redirect-chain evidence; a failed probe leaves the redirect result unknown, not false.
  • auditScope: labels HTTP error-response audits explicitly; headers on a 403 are not proof of the origin application's policy.
  • httpVersion: the negotiated response protocol. The client offers HTTP/2 with ordinary HTTP/1.1 fallback, identifies itself as HiverSecurityAudit, and does not retry access denials with a disguised user agent or another IP.
  • cookies: each final-homepage-response Set-Cookie field, parsed Secure/HttpOnly/SameSite flags, session lifetime and structured findings. SameSite=None without Secure and invalid cookie prefixes are flagged; session-lifetime cookies without HttpOnly are flagged without assuming they are authentication cookies. Intentional client-side state may need JavaScript access. Raw value and evidence include cookie values: treat datasets as potentially sensitive and do not publish them indiscriminately. Redirect-response cookies and browser cookie acceptance outside these static checks are not audited.
  • httpToHttpsRedirect, versionLeaks (server software versions exposed in headers)
  • robotsTxt, sitemapXml, securityTxt (present or not) and the security.txt expiry date

Policy example (real response, shortened)

One GET to https://www.bbc.co.uk/ with the Actor's unchanged identity on 2026-10-07 returned HTTP/2 200. Its script-src includes a nonce, strict-dynamic and unsafe-inline. The effective analysis correctly distinguishes an ignored keyword from permission to run arbitrary inline scripts:

{
"statusCode": 200,
"httpVersion": "HTTP/2",
"policyAnalysis": {
"csp": {
"allowsUnsafeInline": false,
"unsafeInlineIgnored": true
}
}
}

This is a developer diagnostic, not a competitor benchmark. Results vary by response and location.

Price

Pay per event: $2 per 1,000 sites audited (site-audited, $0.002). Sites that do not respond are not charged.

Use it as a CI gate (free GitHub Actions template)

hiver-data/security-headers-ci runs this Actor with your own Apify token after each push to main and every Monday. It writes a grade table to the Actions job summary and fails the job when a site drops below your minimum grade or loses a header you require, such as HSTS or CSP. One to five sites per run: five sites are 5 × $0.002 = $0.01 in site-audited events on the Free plan. The repo's tests replay real rows of this Actor through a local mock API, so you can try the gate without spending anything.

What this is, and is not

  • It reads the response headers and cookies of the home page, and requests /, plain HTTP /, /robots.txt, /sitemap.xml and /.well-known/security.txt. That is all: no scanning of ports or paths, no attack payloads, no login.
  • The score is a simple header checklist (HSTS 20, CSP 25, framing 10, MIME sniffing 10, referrer 10, permissions 5, HTTPS redirect 5, minus points for weak cookies, short HSTS or a missing redirect). It is not a penetration test or vulnerability scan and says nothing about flaws in the application itself.
  • Headers can differ by page, country or bot detection. Sites that block automated requests may show a thin result. A missing header is a finding to review, not proof of a vulnerability.
  • Policy checks are static response-header analysis, not full browser-policy validation: they do not inspect HTML/meta CSP, validate nonce randomness, simulate every source URL intersection, test CSP bypasses or audit TLS configuration. Missing object-src is flagged only when no default-src fallback exists. The presence of a base/object restriction does not mean its allowlist is narrow.
  • Semantics references: CSP3, Set-Cookie, HSTS preload header requirements.
  • The Actor does not read the contact address inside security.txt; it only reports whether the file exists and when it expires.

Input

  • urls: domains or URLs, e.g. github.com
  • maxConcurrency (default 5), timeoutSecs (default 15)

Pricing table & example

Pay per event. Prices per 1,000 events, by Apify plan (higher plans get a discount automatically):

EventFreeStarter (Bronze)Scale (Silver)Business (Gold)
Site audited (site-audited)$2.00$1.80$1.60$1.40

Worked example: 5,000 billable site-audited events on the Free plan cost 5,000 × $0.002 = $10.00; on Gold, 5,000 × $0.0014 = $7.00. Rows that the Price section lists as free cost nothing. Apify platform usage is included in these prices.

Input example

{
"urls": [
"github.com",
"example.com"
]
}

FAQ

Is this a vulnerability scan?
No. It checks public HTTP response headers and hygiene files only. It does not probe for vulnerabilities.

How is the grade calculated?
A fixed weighted checklist, described in this README; it is a hygiene score, not a security guarantee.

Which pages are requested?
The homepage plus robots.txt, sitemap.xml and security.txt.

Is this official?
No. Unofficial and not affiliated with, endorsed by or sponsored by any company or site named in the results or this README.

Something looks wrong or you need a field added?
Open an issue from the Actor's Issues tab with the input and run link.