HSTS Preload Auditor avatar

HSTS Preload Auditor

Pricing

Pay per usage

Go to Apify Store
HSTS Preload Auditor

HSTS Preload Auditor

Audit a public HTTPS URL's HSTS header against hstspreload.org submission requirements. Returns max-age, includeSubDomains, preload eligibility, redirect verification, score, grade, and recommendations.

Pricing

Pay per usage

Rating

0.0

(0)

Developer

Sanskar Jaiswal

Sanskar Jaiswal

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

5 days ago

Last modified

Share

Audits the Strict-Transport-Security (HSTS) configuration of any public HTTPS URL against the hstspreload.org submission requirements and returns a preload readiness score, letter grade, issues, and recommendations as structured JSON.

Use cases

  • Security teams verifying HSTS posture before submitting a domain to the HSTS preload list
  • DevOps engineers checking that HSTS headers survive deploys, CDN cutovers, and origin migrations
  • Site migration QA confirming the plain-HTTP virtual host still redirects to HTTPS on the same host
  • Agency consultants running recurring transport-security checks across client domains
  • CI pipelines gating releases on transport security regressions

Input

FieldTypeDefaultDescription
startUrlstring(required)Public HTTPS URL to audit. A bare hostname gets the https scheme prepended.
timeoutSecondsinteger10Request timeout per request, from 3 to 30 seconds.
checkHttpRedirectbooleantrueAlso request the plain-HTTP version of the host and verify it redirects to HTTPS on the same host, as required for preload submission.
checkWwwSubdomainbooleanfalseAlso request the www subdomain (or the bare domain when the input is www) over HTTPS and verify it responds successfully, since preloading covers all subdomains.

Output

One dataset item per run:

FieldTypeDescription
inputUrlstringURL as provided in the input.
normalizedInputUrlstringURL after scheme normalization and validation.
finalUrlstringFinal URL after redirects of the HTTPS request.
httpsbooleanWhether the final response was served over HTTPS.
okbooleanWhether the audit completed without a fetch or validation error.
checkedAtstringISO 8601 timestamp of the check.
httpStatusinteger or nullHTTP status of the HTTPS response.
hasHstsbooleanWhether a Strict-Transport-Security header was served.
rawHstsstring or nullRaw header value.
maxAgeinteger or nullParsed max-age in seconds.
maxAgeMeetsPreloadbooleanWhether max-age is at least 31536000 (1 year).
includeSubDomainsbooleanWhether the includeSubDomains directive is present.
preloadDirectivebooleanWhether the preload directive is present.
hasExtraDirectivesbooleanWhether unrecognized directives (for example report-uri) are present.
extraDirectivesarrayNames of unrecognized directives.
multipleMaxAgebooleanWhether more than one max-age directive was sent.
classificationstringOne of: preload-eligible, missing, invalid, short-max-age, missing-include-subdomains, missing-preload.
validCertificatebooleanWhether the HTTPS request completed with a valid certificate chain.
httpRedirectCheckedbooleanWhether the HTTP redirect check ran.
httpRedirectOkboolean or nullWhether plain HTTP redirected to HTTPS on the same host.
httpRedirectStatusinteger or nullFinal HTTP status of the redirect check.
httpRedirectTargetstring or nullFinal URL of the redirect check.
wwwSubdomainCheckedbooleanWhether the www subdomain check ran.
wwwSubdomainOkboolean or nullWhether the subdomain responded successfully over HTTPS.
wwwSubdomainStatusinteger or nullHTTP status of the subdomain check.
preloadEligiblebooleanWhether every performed check passed the hstspreload.org requirements.
submissionReadybooleanAlias of preloadEligible.
scoreintegerReadiness score from 0 to 100.
gradestringLetter grade from A+ to F.
issuesarrayConcrete problems found.
recommendationsarrayActionable fixes.
errorstring or nullError message when the audit could not complete.

Example input

{
"startUrl": "https://www.google.com/",
"timeoutSeconds": 10,
"checkHttpRedirect": true,
"checkWwwSubdomain": false
}

Example output

{
"inputUrl": "https://www.google.com/",
"finalUrl": "https://www.google.com/",
"https": true,
"ok": true,
"hasHsts": true,
"maxAge": 31536000,
"maxAgeMeetsPreload": true,
"includeSubDomains": true,
"preloadDirective": true,
"classification": "preload-eligible",
"httpRedirectOk": true,
"preloadEligible": true,
"score": 100,
"grade": "A+",
"issues": [],
"recommendations": [
"HSTS preload requirements are met. Submit the domain at hstspreload.org, then monitor that the header never regresses after deploys."
],
"error": null
}

Security

  • Fetches public HTTP/HTTPS URLs only; URLs with credentials are rejected.
  • Private IPv4, private IPv6, and loopback targets are blocked, hostnames are DNS-resolved, and resolutions to private ranges are rejected (SSRF defense).
  • Every redirect hop is revalidated through the same checks before being followed.
  • No login, no cookies are stored, no JavaScript is executed, and no page content is retained.

Pricing

EventPrice
Actor start$0.005 per run
Domain audited$0.01 per result

A typical single-domain audit costs $0.015.

FAQ

Does this actor submit my domain to the preload list? No. It audits readiness only. Submission happens at hstspreload.org.

Why does a valid HSTS header still not score A+? Preload submission requires more than a header: the HTTP virtual host must redirect to HTTPS on the same host, the certificate chain must be valid, and every subdomain must serve HTTPS. The actor verifies the checks it can perform and reports each one.

What counts as extra directives? Anything other than max-age, includeSubDomains, and preload. RFC 6797 tells browsers to ignore unknown directives, but hstspreload.org expects a clean header, so they are reported as issues.