NEL & Reporting API Auditor avatar

NEL & Reporting API Auditor

Pricing

Pay per usage

Go to Apify Store
NEL & Reporting API Auditor

NEL & Reporting API Auditor

Audit a public URL's Network Error Logging (NEL) and Reporting API configuration in one API call.

Pricing

Pay per usage

Rating

0.0

(0)

Developer

Sanskar Jaiswal

Sanskar Jaiswal

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

2 days ago

Last modified

Share

Audit a public URL's Network Error Logging (NEL) and Reporting API configuration in one API call. Deep-parses the NEL, Report-To, and Reporting-Endpoints response headers, validates endpoint-group wiring against the W3C NEL and Reporting API specs, detects dangling report_to references and report loops, and returns a readiness score, letter grade, and recommendations. Built for web platform engineers, reliability/observability teams, and security/QA consultants.

Use cases

  • Web platform engineers - verify NEL and Report-To wiring before enabling client-side network error telemetry in production
  • Reliability / observability (SRE) teams - confirm report collectors (report-uri.com, self-hosted collectors) are actually referenced by well-formed headers from an external vantage point
  • CDN users - detect Report-To headers auto-attached by CDNs pointing at endpoints you don't control
  • Security/QA consultants - one-shot observability header check that slots into existing header-audit workflows
  • Pre-deploy QA - catch the classic mistake of setting only Reporting-Endpoints, which does not support NEL (it works only with the legacy Report-To pipeline)

What it checks

  • NEL header: valid JSON, required report_to and max_age, boolean include_subdomains, failure_fraction/success_fraction in 0-1, unknown keys, too-short max_age
  • Report-To header (legacy pipeline, required by NEL): group names, max_age, endpoints arrays, https endpoint URLs, duplicate group definitions
  • Reporting-Endpoints header (new pipeline): name="url" entries, https URLs, duplicate names
  • Wiring: NEL report_to must reference a defined Report-To group (dangling references drop reports silently)
  • Pipeline awareness: warns when only Reporting-Endpoints is set — NEL does not work with the new pipeline
  • Report endpoints: https-only URLs, parse validity, and spec-forbidden report loops (endpoints resolving back to the audited origin)

Report endpoints found in headers are never fetched or POSTed to — they are validated as URL strings only, so this actor cannot be used to flood report collectors.

Input

FieldTypeRequiredDefaultDescription
startUrlstringyes-Public URL to audit
timeoutSecondsintegerno10Per-request timeout (3-30 seconds)

Example input

{
"startUrl": "https://example.com",
"timeoutSeconds": 10
}

Output

A single dataset item with the full audit:

FieldTypeDescription
inputUrlstringThe URL provided as input
finalUrlstringFinal URL after redirects
httpsbooleanWhether the final response was served over HTTPS
statusintegerFinal HTTP status code
hasNelbooleanWhether the NEL header is present
hasReportTobooleanWhether the legacy Report-To header is present
hasReportingEndpointsbooleanWhether the new Reporting-Endpoints header is present
nelobjectParsed NEL policy (reportTo, maxAge, includeSubdomains, failureFraction, successFraction, issues)
reportToobjectParsed Report-To groups, endpoints, and issues
reportingEndpointsarrayParsed Reporting-Endpoints named endpoint list
danglingReportTobooleanNEL references a report_to group not defined in Report-To
reportLoopbooleanA report endpoint resolves back to the audited origin (spec violation)
maxAgeinteger | nullParsed NEL max_age (seconds)
includeSubdomainsbooleanNEL include_subdomains flag
endpointCountintegerTotal distinct report endpoints across headers
httpsEndpointCountintegerReport endpoints using https
checksarrayPer-check analysis (name, status, note, weight, recommendation)
issuesarrayAggregated issue descriptions
scoreintegerNEL/Reporting readiness score (0-100)
gradestringLetter grade (A+, A, B, C, D, E, F)
checkedAtstringISO 8601 timestamp
recommendationsarrayActionable recommendations

checks array

FieldDescription
nameCheck title (NEL header, Report-To header, Reporting-Endpoints header, NEL-to-Report-To wiring, Legacy vs new pipeline, Report endpoints)
checkCheck slug
statusgood, warn, missing, or info
noteWhat was found
weightCheck weight in the score
recommendationFix recommendation, or null

Security

  • Public HTTP/HTTPS only; rejects URL credentials, private IP literals, private DNS resolutions, and revalidates redirects before following.
  • Fetches only the provided URL's response headers; report endpoints found in headers are never fetched or POSTed to.
  • No login, no JavaScript execution, no cookies, no stored page content.

Pricing

Pay-per-event: one scored audit per run (~$0.015/run).

Local development

npm install
npm test # node --test suite (parsers, SSRF, scoring, live smoke)
npm run lint # node --check
python3 ../scripts/audit_actor.py . # portfolio security audit (run from actors/ dir)