HSTS Preload Auditor
Pricing
Pay per usage
HSTS Preload Auditor
Audit a public HTTPS URL's HSTS header against hstspreload.org submission requirements. Returns max-age, includeSubDomains, preload eligibility, redirect verification, score, grade, and recommendations.
Pricing
Pay per usage
Rating
0.0
(0)
Developer
Sanskar Jaiswal
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
5 days ago
Last modified
Categories
Share
Audits the Strict-Transport-Security (HSTS) configuration of any public HTTPS URL against the hstspreload.org submission requirements and returns a preload readiness score, letter grade, issues, and recommendations as structured JSON.
Use cases
- Security teams verifying HSTS posture before submitting a domain to the HSTS preload list
- DevOps engineers checking that HSTS headers survive deploys, CDN cutovers, and origin migrations
- Site migration QA confirming the plain-HTTP virtual host still redirects to HTTPS on the same host
- Agency consultants running recurring transport-security checks across client domains
- CI pipelines gating releases on transport security regressions
Input
| Field | Type | Default | Description |
|---|---|---|---|
| startUrl | string | (required) | Public HTTPS URL to audit. A bare hostname gets the https scheme prepended. |
| timeoutSeconds | integer | 10 | Request timeout per request, from 3 to 30 seconds. |
| checkHttpRedirect | boolean | true | Also request the plain-HTTP version of the host and verify it redirects to HTTPS on the same host, as required for preload submission. |
| checkWwwSubdomain | boolean | false | Also request the www subdomain (or the bare domain when the input is www) over HTTPS and verify it responds successfully, since preloading covers all subdomains. |
Output
One dataset item per run:
| Field | Type | Description |
|---|---|---|
| inputUrl | string | URL as provided in the input. |
| normalizedInputUrl | string | URL after scheme normalization and validation. |
| finalUrl | string | Final URL after redirects of the HTTPS request. |
| https | boolean | Whether the final response was served over HTTPS. |
| ok | boolean | Whether the audit completed without a fetch or validation error. |
| checkedAt | string | ISO 8601 timestamp of the check. |
| httpStatus | integer or null | HTTP status of the HTTPS response. |
| hasHsts | boolean | Whether a Strict-Transport-Security header was served. |
| rawHsts | string or null | Raw header value. |
| maxAge | integer or null | Parsed max-age in seconds. |
| maxAgeMeetsPreload | boolean | Whether max-age is at least 31536000 (1 year). |
| includeSubDomains | boolean | Whether the includeSubDomains directive is present. |
| preloadDirective | boolean | Whether the preload directive is present. |
| hasExtraDirectives | boolean | Whether unrecognized directives (for example report-uri) are present. |
| extraDirectives | array | Names of unrecognized directives. |
| multipleMaxAge | boolean | Whether more than one max-age directive was sent. |
| classification | string | One of: preload-eligible, missing, invalid, short-max-age, missing-include-subdomains, missing-preload. |
| validCertificate | boolean | Whether the HTTPS request completed with a valid certificate chain. |
| httpRedirectChecked | boolean | Whether the HTTP redirect check ran. |
| httpRedirectOk | boolean or null | Whether plain HTTP redirected to HTTPS on the same host. |
| httpRedirectStatus | integer or null | Final HTTP status of the redirect check. |
| httpRedirectTarget | string or null | Final URL of the redirect check. |
| wwwSubdomainChecked | boolean | Whether the www subdomain check ran. |
| wwwSubdomainOk | boolean or null | Whether the subdomain responded successfully over HTTPS. |
| wwwSubdomainStatus | integer or null | HTTP status of the subdomain check. |
| preloadEligible | boolean | Whether every performed check passed the hstspreload.org requirements. |
| submissionReady | boolean | Alias of preloadEligible. |
| score | integer | Readiness score from 0 to 100. |
| grade | string | Letter grade from A+ to F. |
| issues | array | Concrete problems found. |
| recommendations | array | Actionable fixes. |
| error | string or null | Error message when the audit could not complete. |
Example input
{"startUrl": "https://www.google.com/","timeoutSeconds": 10,"checkHttpRedirect": true,"checkWwwSubdomain": false}
Example output
{"inputUrl": "https://www.google.com/","finalUrl": "https://www.google.com/","https": true,"ok": true,"hasHsts": true,"maxAge": 31536000,"maxAgeMeetsPreload": true,"includeSubDomains": true,"preloadDirective": true,"classification": "preload-eligible","httpRedirectOk": true,"preloadEligible": true,"score": 100,"grade": "A+","issues": [],"recommendations": ["HSTS preload requirements are met. Submit the domain at hstspreload.org, then monitor that the header never regresses after deploys."],"error": null}
Security
- Fetches public HTTP/HTTPS URLs only; URLs with credentials are rejected.
- Private IPv4, private IPv6, and loopback targets are blocked, hostnames are DNS-resolved, and resolutions to private ranges are rejected (SSRF defense).
- Every redirect hop is revalidated through the same checks before being followed.
- No login, no cookies are stored, no JavaScript is executed, and no page content is retained.
Pricing
| Event | Price |
|---|---|
| Actor start | $0.005 per run |
| Domain audited | $0.01 per result |
A typical single-domain audit costs $0.015.
FAQ
Does this actor submit my domain to the preload list? No. It audits readiness only. Submission happens at hstspreload.org.
Why does a valid HSTS header still not score A+? Preload submission requires more than a header: the HTTP virtual host must redirect to HTTPS on the same host, the certificate chain must be valid, and every subdomain must serve HTTPS. The actor verifies the checks it can perform and reports each one.
What counts as extra directives? Anything other than max-age, includeSubDomains, and preload. RFC 6797 tells browsers to ignore unknown directives, but hstspreload.org expects a clean header, so they are reported as issues.