HTTP Security Headers & Posture Checker avatar

HTTP Security Headers & Posture Checker

Pricing

from $4.20 / 1,000 results

Go to Apify Store
HTTP Security Headers & Posture Checker

HTTP Security Headers & Posture Checker

A direct website security preflight: URLs in, structured HTTP security posture out. Drift monitoring is optional rather than the core entry point.

Pricing

from $4.20 / 1,000 results

Rating

0.0

(0)

Developer

Rafael Barreto Haddad

Rafael Barreto Haddad

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

2 days ago

Last modified

Share

A direct website security preflight: URLs in, structured HTTP security posture out. Drift monitoring is optional rather than the core entry point.

Give public URLs. Check HTTP security headers and posture, return structured risks and scores, with optional regression comparison across runs.

Why use this Actor

A site can pass a header audit today and regress tomorrow after a CDN, framework, reverse proxy or deployment change. Security teams also need to know whether TLS certificates are expiring, cookies lost protective flags, CORS became dangerous, or a security.txt contact disappeared. This Actor produces one normalized posture record per target and makes those records reusable as baselines.

Key features

  • Weighted security-header posture across HSTS, CSP, frame protection, referrer policy, permissions policy and cross-origin isolation headers.
  • TLS protocol and certificate-expiry evidence.
  • Cookie Secure, HttpOnly and SameSite checks.
  • CORS probe for dangerous wildcard-plus-credentials behavior.
  • .well-known/security.txt presence and basic validity check.
  • Posture score, grade, severity, regression delta and deterministic baseline fingerprint.
  • Multi-domain portfolio average, critical count and regression count.
  • Related-framework hints for OWASP, CIS, NIST and PCI DSS without pretending to certify compliance.
  • agentAction and agentReason fields for automation and AI-agent routing.

Input

Provide one or more public URLs. For recurring monitoring, feed previous snapshots back through previousSnapshots. Optional gates can fail a run after results are written when a critical posture or regression is detected.

Output

One structured row per target containing posture score, grade, severity, header evidence, TLS evidence, cookie findings, CORS findings, security.txt evidence, portfolio context, reusable snapshot and recommended action.

Example

Audit https://www.python.org, save its currentSnapshot, then reuse that object on a later scheduled run to detect posture deterioration.

Use cases

DevSecOps release gates, security hygiene monitoring, vendor and third-party risk, agency/MSSP portfolio checks, due-diligence evidence, certificate-expiry monitoring, public-surface compliance evidence and AI-agent remediation workflows.

Pricing

Pay per audited target result. The Actor uses a lean HTTP-first runtime and avoids browser or paid-LLM costs for the normal path.

Limitations

This is not penetration testing, vulnerability exploitation, authenticated scanning or a compliance certification. Public responses can vary by geography, CDN, authentication and HTTP method. Framework mappings indicate related controls only.