NEL & Reporting API Auditor
Pricing
Pay per usage
NEL & Reporting API Auditor
Audit a public URL's Network Error Logging (NEL) and Reporting API configuration in one API call.
Pricing
Pay per usage
Rating
0.0
(0)
Developer
Sanskar Jaiswal
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
2 days ago
Last modified
Categories
Share
Audit a public URL's Network Error Logging (NEL) and Reporting API configuration in one API call. Deep-parses the NEL, Report-To, and Reporting-Endpoints response headers, validates endpoint-group wiring against the W3C NEL and Reporting API specs, detects dangling report_to references and report loops, and returns a readiness score, letter grade, and recommendations. Built for web platform engineers, reliability/observability teams, and security/QA consultants.
Use cases
- Web platform engineers - verify NEL and Report-To wiring before enabling client-side network error telemetry in production
- Reliability / observability (SRE) teams - confirm report collectors (report-uri.com, self-hosted collectors) are actually referenced by well-formed headers from an external vantage point
- CDN users - detect
Report-Toheaders auto-attached by CDNs pointing at endpoints you don't control - Security/QA consultants - one-shot observability header check that slots into existing header-audit workflows
- Pre-deploy QA - catch the classic mistake of setting only
Reporting-Endpoints, which does not support NEL (it works only with the legacyReport-Topipeline)
What it checks
NELheader: valid JSON, requiredreport_toandmax_age, booleaninclude_subdomains,failure_fraction/success_fractionin 0-1, unknown keys, too-shortmax_ageReport-Toheader (legacy pipeline, required by NEL): group names,max_age,endpointsarrays, https endpoint URLs, duplicate group definitionsReporting-Endpointsheader (new pipeline):name="url"entries, https URLs, duplicate names- Wiring: NEL
report_tomust reference a defined Report-To group (dangling references drop reports silently) - Pipeline awareness: warns when only
Reporting-Endpointsis set — NEL does not work with the new pipeline - Report endpoints: https-only URLs, parse validity, and spec-forbidden report loops (endpoints resolving back to the audited origin)
Report endpoints found in headers are never fetched or POSTed to — they are validated as URL strings only, so this actor cannot be used to flood report collectors.
Input
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
startUrl | string | yes | - | Public URL to audit |
timeoutSeconds | integer | no | 10 | Per-request timeout (3-30 seconds) |
Example input
{"startUrl": "https://example.com","timeoutSeconds": 10}
Output
A single dataset item with the full audit:
| Field | Type | Description |
|---|---|---|
inputUrl | string | The URL provided as input |
finalUrl | string | Final URL after redirects |
https | boolean | Whether the final response was served over HTTPS |
status | integer | Final HTTP status code |
hasNel | boolean | Whether the NEL header is present |
hasReportTo | boolean | Whether the legacy Report-To header is present |
hasReportingEndpoints | boolean | Whether the new Reporting-Endpoints header is present |
nel | object | Parsed NEL policy (reportTo, maxAge, includeSubdomains, failureFraction, successFraction, issues) |
reportTo | object | Parsed Report-To groups, endpoints, and issues |
reportingEndpoints | array | Parsed Reporting-Endpoints named endpoint list |
danglingReportTo | boolean | NEL references a report_to group not defined in Report-To |
reportLoop | boolean | A report endpoint resolves back to the audited origin (spec violation) |
maxAge | integer | null | Parsed NEL max_age (seconds) |
includeSubdomains | boolean | NEL include_subdomains flag |
endpointCount | integer | Total distinct report endpoints across headers |
httpsEndpointCount | integer | Report endpoints using https |
checks | array | Per-check analysis (name, status, note, weight, recommendation) |
issues | array | Aggregated issue descriptions |
score | integer | NEL/Reporting readiness score (0-100) |
grade | string | Letter grade (A+, A, B, C, D, E, F) |
checkedAt | string | ISO 8601 timestamp |
recommendations | array | Actionable recommendations |
checks array
| Field | Description |
|---|---|
name | Check title (NEL header, Report-To header, Reporting-Endpoints header, NEL-to-Report-To wiring, Legacy vs new pipeline, Report endpoints) |
check | Check slug |
status | good, warn, missing, or info |
note | What was found |
weight | Check weight in the score |
recommendation | Fix recommendation, or null |
Security
- Public HTTP/HTTPS only; rejects URL credentials, private IP literals, private DNS resolutions, and revalidates redirects before following.
- Fetches only the provided URL's response headers; report endpoints found in headers are never fetched or POSTed to.
- No login, no JavaScript execution, no cookies, no stored page content.
Pricing
Pay-per-event: one scored audit per run (~$0.015/run).
Local development
npm installnpm test # node --test suite (parsers, SSRF, scoring, live smoke)npm run lint # node --checkpython3 ../scripts/audit_actor.py . # portfolio security audit (run from actors/ dir)