← All projects
Security & networking · Python
HS

headerscan

HTTP security header grader — paste response headers, get an A–F grade and the exact fix for every finding. No network needed.

Grade a response

Result

F
20/100http://127.0.0.1:8011 (HTTP 200)

Scoring

Score starts at 100 and subtracts per finding:

SeverityPenalty
high−20
medium−10
low−5
info0

Grades: A ≥ 90, B ≥ 80, C ≥ 65, D ≥ 50, else F.

What it checks

  • HTTPS in use · HSTS (max-age ≥ 180 days)
  • CSP: present, no bare unsafe-inline, no wildcard script hosts
  • X-Content-Type-Options: nosniff
  • Clickjacking: XFO or CSP frame-ancestors
  • Referrer-Policy, Permissions-Policy
  • Version numbers in Server / X-Powered-By
  • Cookies: Secure, HttpOnly, SameSite

The CLI sends one GET per URL — only scan sites you own or have permission to test.

10 tests · Python 3.10+ · CI-friendly exit codes · Built by Umer Hashmi