URL Redirect Chain Analyzer — Trace & Security Check avatar

URL Redirect Chain Analyzer — Trace & Security Check

Pricing

from $0.025 / actor start

Go to Apify Store
URL Redirect Chain Analyzer — Trace & Security Check

URL Redirect Chain Analyzer — Trace & Security Check

Trace HTTP redirect chains for any URL. Detects redirect loops, insecure http downgrades, open redirect vulnerabilities, and tracking/analytics parameters. Supports single and batch mode (up to 50 URLs). Returns full hop-by-hop chain with security grading.

Pricing

from $0.025 / actor start

Rating

0.0

(0)

Developer

Perry AY

Perry AY

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

12 hours ago

Last modified

Share

URL Redirect Chain Analyzer — Trace, Security & SEO Redirect Analysis

Trace and analyze HTTP redirect chains for any URL. Detect redirect loops, insecure HTTP downgrades, open redirect vulnerabilities, and tracking/analytics parameters. Works with single URLs or batch mode up to 50 URLs.

Built with async HTTPX for non-blocking redirect tracing. No Playwright, no browser automation. Each hop is captured manually for full visibility into the redirect chain.


What does it do?

URL Redirect Chain Analyzer takes one or more URLs and follows their HTTP redirect chains hop by hop (301, 302, 303, 307, 308). For each URL it produces a complete chain with status codes, response headers, security grading, and vulnerability detection. It strips tracking parameters from final URLs and assigns a security grade from A (secure) to F (critical).


Features

  1. Full redirect chain tracing — Follows every hop from initial URL to final destination, capturing status codes and headers per hop
  2. Redirect loop detection — Identifies cyclic redirects that would cause browser timeouts
  3. Insecure downgrade detection — Flags transitions from HTTPS to HTTP that expose traffic
  4. Open redirect vulnerability check — Detects redirects to completely different domains or non-HTTP schemes
  5. Tracking parameter detection — Identifies and removes 40+ known analytics/tracking parameters (UTM, Facebook, Google Ads, HubSpot, etc.)
  6. Security grading (A–F) — Automated security score based on chain complexity, vulnerabilities, and protocol usage
  7. DNS resolution — Resolves the final hostname to an IP address for additional context
  8. Batch mode — Process up to 50 URLs in a single run with concurrent tracing
  9. Hop-by-hop headers — Captures Location, Content-Type, Set-Cookie, Cache-Control, Server, X-Redirect-By, and X-Frame-Options at each step
  10. Graceful error isolation — A failed URL never blocks the rest of the batch

Why use this?

Pain PointHow This Actor Solves It
Manual curl/wget tracing is slow and doesn't scaleAutomated batch analysis traces up to 50 URLs with concurrent requests
SEO teams need to audit redirect chains for link equity lossChain length and status codes enable quick assessment of redirect health
Security teams need to scan for open redirectsBuilt-in open redirect detection and security grading
Marketing teams want clean, tracking-free URLsAutomatic detection and stripping of 40+ tracking parameters
DevOps needs to monitor redirect chain health over timeStructured JSON output feeds dashboards and monitoring pipelines
Developers debugging redirect logic need hop-by-hop visibilityFull per-hop capture with headers, status codes, and timing

Who is it for?

PersonaWhat They Use It For
SEO specialistAudit redirect chains to assess link equity loss and identify broken redirects
Security engineerScan for open redirect vulnerabilities that could be used in phishing attacks
Marketing analystStrip tracking parameters from campaign URLs for clean analytics data
Web developerDebug redirect logic during site migrations or URL restructuring
DevOps engineerMonitor redirect chain health in CI/CD pipelines and uptime checks
Penetration testerIdentify insecure redirect paths and protocol downgrade vulnerabilities
Content managerVerify that bookmarked URLs, shortened links, and redirects still work correctly

Input Parameters

FieldTypeRequiredDefaultDescription
modestring (enum)Yessinglesingle or batch
urlstringIf mode=singleFull URL with scheme (https://example.com/path)
urlsarray of stringsIf mode=batch[]List of URLs to trace (max 50)
security_scanbooleanNofalseEnable advanced security analysis and grading

Example Input

Single mode:

{
"mode": "single",
"url": "https://example.com/redirect-test",
"security_scan": true
}

Batch mode:

{
"mode": "batch",
"urls": [
"https://example.com/redirect-test",
"https://example.com",
"https://example.com/shortcut"
],
"security_scan": true
}

Output Format

Each dataset row is one analyzed URL with the following fields:

FieldTypeDescription
input_urlstringThe original URL submitted for analysis
final_urlstringFinal URL after all redirects (or the original if no redirect)
chain_lengthintegerNumber of redirect hops (0 if no redirect)
has_redirectbooleanTrue if at least one redirect was followed
is_loopbooleanTrue if a redirect loop was detected
is_open_redirectbooleanTrue if a potential open redirect was found
has_insecure_downgradebooleanTrue if a HTTPS→HTTP downgrade occurred
has_tracking_paramsbooleanTrue if tracking/analytics parameters were found in the final URL
tracking_params_foundarrayList of detected tracking parameter names
stripped_urlstringFinal URL with tracking parameters removed
final_status_codeintegerHTTP status code of the final response
security_gradestringSecurity grade: A (secure), B, C, D, or F (critical)
total_duration_msnumberTotal time to trace the full chain in milliseconds
dns_resolved_tostringResolved IP address of the final hostname
warningsarrayList of warning messages (loops, downgrades, etc.)
errorstringError message if the analysis failed (empty on success)
hopsarrayArray of hop objects with step, url, status_code, headers, and flags per redirect

Each hop object in the hops array contains:

FieldTypeDescription
stepintegerStep number in the redirect chain (starting at 0)
urlstringThe URL at this hop
status_codeinteger or nullHTTP status code of the response
headersobjectResponse headers (Location, Content-Type, etc.)
is_securebooleanWhether this hop used HTTPS
is_insecurebooleanWhether this hop used HTTP
is_loopbooleanTrue if this hop created a redirect loop

Example Output

{
"input_url": "https://example.com/redirect-test",
"final_url": "https://example.com/final",
"chain_length": 2,
"has_redirect": true,
"is_loop": false,
"is_open_redirect": false,
"has_insecure_downgrade": false,
"has_tracking_params": false,
"tracking_params_found": [],
"stripped_url": "https://example.com/final",
"final_status_code": 200,
"security_grade": "A",
"total_duration_ms": 312.5,
"dns_resolved_to": "93.184.216.34",
"warnings": [],
"error": "",
"hops": [
{
"step": 0,
"url": "https://example.com/redirect-test",
"status_code": 302,
"headers": {"location": "/intermediate", "server": "nginx"},
"is_secure": true,
"is_insecure": false,
"is_loop": false
},
{
"step": 1,
"url": "https://example.com/intermediate",
"status_code": 301,
"headers": {"location": "/final"},
"is_secure": true,
"is_insecure": false,
"is_loop": false
},
{
"step": 2,
"url": "https://example.com/final",
"status_code": 200,
"headers": {"content-type": "text/html"},
"is_secure": true,
"is_insecure": false,
"is_loop": false
}
]
}

API Usage

cURL

curl -X POST "https://api.apify.com/v2/acts/perryay~url-redirect-chain-analyzer/runs" \
-H "Content-Type: application/json" \
-d '{
"mode": "single",
"url": "https://example.com/redirect-test",
"security_scan": true
}'

Python (ApifyClient)

from apify_client import ApifyClient
client = ApifyClient("YOUR_API_TOKEN")
run = client.actor("perryay/url-redirect-chain-analyzer").call(
run_input={
"mode": "single",
"url": "https://example.com/redirect-test",
"security_scan": True,
}
)
dataset_items = client.dataset(run["defaultDatasetId"]).list_items().items
for item in dataset_items:
print(f"{item['input_url']}{item['final_url']} [Grade: {item['security_grade']}]")

Node.js

const ApifyClient = require('apify-client').ApifyClient;
const client = new ApifyClient({ token: 'YOUR_API_TOKEN' });
const run = await client.actor('perryay/url-redirect-chain-analyzer').call({
mode: 'single',
url: 'https://example.com/redirect-test',
security_scan: true,
});
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach(item => console.log(`${item.input_url}${item.final_url} [Grade: ${item.security_grade}]`));

Use Cases

1. SEO Redirect Audit

When migrating a website or restructuring URLs, SEO teams need to verify that all old URLs properly redirect to new ones without excessive chain depths that dilute link equity. Run a batch of 50 URLs through this actor and inspect chain_length, status codes, and final_urls to validate the migration.

2. Security Vulnerability Scanning

Open redirect vulnerabilities are a common finding in penetration tests. Enable security_scan mode to automatically flag redirects that point to completely different domains or use non-standard schemes. The security grade column makes triage immediate.

3. Marketing Campaign URL Cleanup

Marketing tools often append tracking parameters (UTM, fbclid, gclid) to URLs. Use this actor to identify tracking parameters and produce clean, stripped URLs for canonical references, analytics deduplication, or sharing.

4. CDN and Load Balancer Debugging

Content delivery networks and load balancers often add redirect hops. Development and DevOps teams can trace URLs through these systems to verify that geo-redirects, A/B testing redirects, and protocol upgrades work correctly.

Trace bit.ly, tinyurl, and other shortened URLs to their final destinations. Detect if shortened links redirect through multiple services, whether they have tracking parameters appended, and whether the final destination is legitimate or potentially malicious.

6. Downtime Monitoring

Configure a recurring Apify schedule to trace critical URLs daily. Any change in chain length, final URL, or status code triggers an investigation — helping catch misconfigured redirects before users notice.

7. Quality Assurance

During site launches or feature deployments, QA teams can batch-test dozens of URLs to verify that redirect logic works as specified, catching bugs like missing trailing slash redirects, protocol mismatches, or unintended external redirects.

8. Compliance Auditing

Regulatory frameworks (PCI DSS, SOC 2, ISO 27001) often require verification that sensitive endpoints don't redirect to insecure protocols. Security audit mode documents the redirect posture of critical URLs for compliance reports.


FAQ

1. What redirect status codes are followed?

301 (Moved Permanently), 302 (Found), 303 (See Other), 307 (Temporary Redirect), and 308 (Permanent Redirect).

2. What is the maximum redirect depth?

The actor follows up to 20 consecutive redirects before reporting an error. This is the browser-standard limit.

3. What tracking parameters are detected?

Over 40 known parameters: UTM tags (utm_source, utm_medium, utm_campaign, utm_term, utm_content), Facebook click IDs (fbclid), Google Click IDs (gclid, gclsrc), Microsoft Click IDs (msclkid), and many more.

4. How is the security grade calculated?

  • A — No issues, chain length ≤ 2, no tracking parameters, no downgrade
  • B — Minor issues (tracking parameters found, or chain length 3–5)
  • C — Warnings (chain length > 5, no other issues)
  • D — Insecure downgrade detected (HTTPS → HTTP)
  • F — Critical (open redirect or redirect loop detected)

5. Does this actor follow redirects in the browser?

No. All redirect tracing is done server-side using HTTPX without JavaScript execution. This is intentional — it avoids the overhead of Playwright and gives deterministic results based on HTTP-level redirects only.

6. What happens if a URL times out?

The actor has a 15-second timeout per HTTP request. If a single hop times out, the error is recorded per-URL and the actor continues processing other URLs in the batch.

7. Can this actor detect JavaScript-based redirects (window.location)?

No. JavaScript-based redirects are not detectable server-side. This actor focuses on HTTP-level redirects (status codes 3xx).

8. What is the difference between single and batch mode?

In single mode, you submit one URL at a time. In batch mode, you can submit up to 50 URLs in a single run, and they are processed concurrently (up to 5 at a time) for faster throughput.

9. How accurate is the open redirect detection?

The actor flags potential open redirects when a redirect Location header points to a completely different domain or uses a non-standard scheme. This is a heuristic — false positives are possible when legitimate cross-domain redirects occur (e.g., OAuth flows).

10. Can I integrate this into a CI/CD pipeline?

Yes. The actor can be called via the Apify API with a simple POST request. The structured JSON output integrates naturally with monitoring systems, dashboards, and alerting tools.


MCP Integration

Add this actor to your MCP (Model Context Protocol) server configuration:

{
"mcpServers": {
"apify-redirect-analyzer": {
"command": "npx",
"args": [
"-y",
"@apify/mcp-server-actors",
"--actors=perryay/url-redirect-chain-analyzer"
]
}
}
}


SEO Keywords

URL redirect chain analyzer, redirect tracer, HTTP redirect checker, redirect loop detection, open redirect vulnerability scanner, tracking parameter stripper, UTM cleanup tool, URL security analysis, redirect audit tool, SEO redirect checker, batch URL redirect analyzer, HTTP status code checker, link shortener expander, redirect chain depth tool