Go to example tasks

CSP and HSTS checker for a list of client sites

For agencies and security consultants: parse each site's Content-Security-Policy (unsafe-inline, nonce, hash, strict-dynamic, frame-ancestors, base-uri) and HSTS (max-age, includeSubDomains, preload). Findings carry a severity and the exact header they came from, plus whether the site publishes security.txt. $2 per 1,000 sites audited on the free plan.

Try for free
Security Headers Checker: Website Audit for CSP & HSTS
Security Headers Checker: Website Audit for CSP & HSTShiver/website-security-headers-audit
Site
Success
Grade
Score
+4 fields
Text
Number
Boolean
List
Object

Input

Websites(required):stripe.com+2
Parallel sites:3

Output fields

Site
Success
Grade
Score
Issues
HTTP→HTTPS
security.txt
Error

How it works

Sign up on Apify01

Create your Apify account to access the Security Headers Checker: Website Audit for CSP & HSTS.

Start the run02

The Actor will start running based on the input automatically.

Receive the output03

Monitor the progress in real-time. You will be notified as soon as your dataset is complete and ready for review.

Integrate into your workflow04

The final output is delivered in JSON, CSV, or Excel format, ready to be plugged into your workflow.

Image

Integrate Actor directly into your workflow

Choose from one of 100+ integration options we provide or integrate via API

Webhook

Webhook

n8n

n8n

Make

Make

Zapier

Zapier

Airbyte

Airbyte

Keboola

Keboola

IFTTT

IFTTT

Hubspot

Hubspot

GDrive

GDrive

Gmail

Gmail

Apify MCP

Apify MCP

GitHub

GitHub

Slack

Slack

LangChain

LangChain

LlamaIndex

LlamaIndex

Flowise

Flowise

Pinecone

Pinecone

OpenAI

OpenAI

Mastra

Mastra

Clay

Clay