# HTTP Security Headers & Posture Checker (`quanmatrix/http-security-baseline-drift-monitor`) Actor

A direct website security preflight: URLs in, structured HTTP security posture out. Drift monitoring is optional rather than the core entry point.

- **URL**: https://apify.com/quanmatrix/http-security-baseline-drift-monitor.md
- **Developed by:** [Rafael Barreto Haddad](https://apify.com/quanmatrix) (community)
- **Categories:** Developer tools, Automation
- **Stats:** 2 total users, 1 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

from $4.20 / 1,000 results

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.
Since this Actor supports Apify Store discounts, the price gets lower the higher subscription plan you have.

Learn more: https://docs.apify.com/actors/running/actors-in-store.md#pay-per-event

## What's an Apify Actor?

An Actor is a serverless cloud program that runs on the Apify platform. It has two run modes.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.

Apify vocabulary and the platform model are defined once, in the agent quickstart at https://apify.com/agents.md.

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.

Do not guess an integration path. Every one of them is in the agent quickstart at https://apify.com/agents.md: the Apify MCP server, Agent Skills with the Apify CLI, the JavaScript and Python clients, the REST API, and the account-free path for an agent with no human to sign in. It also carries the rule on stating cost before the first paid run.

For examples already wired to this Actor's own input schema, see the [API](#api) section below.

Each client library has reference documentation the quickstart does not restate: [JavaScript/TypeScript](https://docs.apify.com/api/client/js/docs.md) (`npm install apify-client`) and [Python](https://docs.apify.com/api/client/python/docs.md) (`pip install apify-client`).

# README

## HTTP Security Headers & Posture Checker

A direct website security preflight: URLs in, structured HTTP security posture out. Drift monitoring is optional rather than the core entry point.

Give public URLs. Check HTTP security headers and posture, return structured risks and scores, with optional regression comparison across runs.

### Why use this Actor

A site can pass a header audit today and regress tomorrow after a CDN, framework, reverse proxy or deployment change. Security teams also need to know whether TLS certificates are expiring, cookies lost protective flags, CORS became dangerous, or a security.txt contact disappeared. This Actor produces one normalized posture record per target and makes those records reusable as baselines.

### Key features

- Weighted security-header posture across HSTS, CSP, frame protection, referrer policy, permissions policy and cross-origin isolation headers.
- TLS protocol and certificate-expiry evidence.
- Cookie Secure, HttpOnly and SameSite checks.
- CORS probe for dangerous wildcard-plus-credentials behavior.
- `.well-known/security.txt` presence and basic validity check.
- Posture score, grade, severity, regression delta and deterministic baseline fingerprint.
- Multi-domain portfolio average, critical count and regression count.
- Related-framework hints for OWASP, CIS, NIST and PCI DSS without pretending to certify compliance.
- `agentAction` and `agentReason` fields for automation and AI-agent routing.

### Input

Provide one or more public URLs. For recurring monitoring, feed previous snapshots back through `previousSnapshots`. Optional gates can fail a run after results are written when a critical posture or regression is detected.

### Output

One structured row per target containing posture score, grade, severity, header evidence, TLS evidence, cookie findings, CORS findings, security.txt evidence, portfolio context, reusable snapshot and recommended action.

### Example

Audit `https://www.python.org`, save its `currentSnapshot`, then reuse that object on a later scheduled run to detect posture deterioration.

### Use cases

DevSecOps release gates, security hygiene monitoring, vendor and third-party risk, agency/MSSP portfolio checks, due-diligence evidence, certificate-expiry monitoring, public-surface compliance evidence and AI-agent remediation workflows.

### Pricing

Pay per audited target result. The Actor uses a lean HTTP-first runtime and avoids browser or paid-LLM costs for the normal path.

### Limitations

This is not penetration testing, vulnerability exploitation, authenticated scanning or a compliance certification. Public responses can vary by geography, CDN, authentication and HTTP method. Framework mappings indicate related controls only.

# Changelog

This Actor's version history is a separate document: https://apify.com/quanmatrix/http-security-baseline-drift-monitor/changelog.md

# Actor input Schema

## `urls` (type: `array`):

Public HTTP(S) targets to audit.

## `url` (type: `string`):

Optional single public target.

## `maxUrls` (type: `integer`):

Maximum targets in one run.

## `previousSnapshots` (type: `object`):

Optional map from URL to prior snapshot for regression detection.

## `failRunOnCritical` (type: `boolean`):

Fail after writing results if any target is critical.

## `failRunOnRegression` (type: `boolean`):

Fail after writing results if posture deteriorates.

## `concurrency` (type: `integer`):

Maximum target audits processed in parallel.

## `minimumPostureScore` (type: `number`):

Threshold used by failRunBelowScore.

## `failRunBelowScore` (type: `boolean`):

Fail after writing evidence if any target is below minimumPostureScore.

## `mcpConnectors` (type: `array`):

Optional MCP connectors authorized in your Apify account. Use them to send or write this Actor result to tools such as Slack, Notion, GitHub, Sentry, Supabase, or another compatible MCP service.

## `mcpToolName` (type: `string`):

Optional exact MCP tool name. Leave blank to let the selected MCP action preset discover a compatible tool automatically.

## `mcpToolArguments` (type: `object`):

JSON object passed to the selected MCP tool. String values may use {{actor\_title}}, {{result\_summary}}, or {{result\_json}} placeholders.

## `mcpFailOnError` (type: `boolean`):

When enabled, an MCP delivery error fails the Actor run. Disabled by default so data extraction and intelligence results remain available even if the external destination is unavailable.

## `mcpActionPreset` (type: `string`):

Choose a safe action pattern. AUTO\_SAFE\_WRITE discovers a compatible non-destructive write tool automatically; use a specific preset for Slack, GitHub, Notion, or database delivery.

## Actor input object example

```json
{
  "urls": [
    "https://www.python.org"
  ],
  "maxUrls": 50,
  "failRunOnCritical": false,
  "failRunOnRegression": false,
  "concurrency": 4,
  "minimumPostureScore": 70,
  "failRunBelowScore": false,
  "mcpToolName": "",
  "mcpToolArguments": {},
  "mcpFailOnError": false,
  "mcpActionPreset": "AUTO_SAFE_WRITE"
}
```

# Actor output Schema

## `results` (type: `string`):

No description

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {};

// Run the Actor and wait for it to finish
const run = await client.actor("quanmatrix/http-security-baseline-drift-monitor").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = {}

# Run the Actor and wait for it to finish
run = client.actor("quanmatrix/http-security-baseline-drift-monitor").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print(f"💾 Check your data here: https://console.apify.com/storage/datasets/{run.default_dataset_id}")
for item in client.dataset(run.default_dataset_id).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{}' |
apify call quanmatrix/http-security-baseline-drift-monitor --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "type": "http",
            "url": "https://mcp.apify.com/?tools=fetch-actor-details,quanmatrix/http-security-baseline-drift-monitor"
        }
    }
}
```

The hosted server signs you in with OAuth on first connect, so no API token belongs in this config. Clients without OAuth support can send an `Authorization: Bearer <APIFY_API_TOKEN>` header instead, using a token from API & Integrations in Apify Console (https://console.apify.com/settings/integrations).

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/actors/WbEjWEKCNadJnZB7o/builds/5u4GnYz5yMQhe3uSu/openapi.json
