82trust / 100

Security Headers Analyze

by NetIntel in Security & trust

x402 APIPassing, checked 38 min ago

Fetches a URL and evaluates 10 security-critical response headers (CSP, HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, X-XSS-Protection, CORP, COEP, COOP), detects anti-patterns, and returns an overall security grade (A–F).

GET https://netintel.dev/security-headers/analyze

Last 30 days

All checks passedSome failedAll failedNot checked
Uptime
100%
Response time
181 ms typical, 181 ms slowest 5%
Last check
38 min ago
Next check
any minute now

How to call it

# See the payment challenge (nothing is charged)
curl -i -X GET "https://netintel.dev/security-headers/analyze?target=https%3A%2F%2Fexample.com"
import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { ExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";

const client = new x402Client().register(
  "eip155:8453",
  new ExactEvmScheme(privateKeyToAccount(process.env.AGENT_KEY)),
);
const pay = wrapFetchWithPayment(fetch, client);

// Not sure it's safe to pay? Preflight it first for $0.005:
// GET https://toolvet.app/api/v1/check?url=https%3A%2F%2Fnetintel.dev%2Fsecurity-headers%2Fanalyze
const res = await pay("https://netintel.dev/security-headers/analyze?target=https%3A%2F%2Fexample.com");
console.log(await res.json());

Example input

{
  "target": "https://example.com"
}

Example output

{
  "deductions": [
    {
      "points": -5,
      "reason": "Permissions-Policy not set"
    },
    {
      "points": -2,
      "reason": "Cross-Origin-Resource-Policy not set"
    },
    {
      "points": -2,
      "reason": "Cross-Origin-Embedder-Policy not set"
    },
    {
      "points": -2,
      "reason": "Cross-Origin-Opener-Policy not set"
    },
    {
      "points": -3,
      "reason": "X-Powered-By header exposes server framework"
    }
  ],
  "errors": [],
  "grade": "B",
  "meta": {
    "duration_ms": 312
  },
  "results": {
    "anti_patterns": [
      {
        "header": "x-powered-by",
        "raw_value": "Express",
        "reason": "Information leakage — reveals server framework",
        "severity": "warn"
      }
    ],
    "content_type": "text/html; charset=utf-8",
    "final_url": "https://example.com/",
    "headers": {
      "content-security-policy": {
        "present": true,
        "raw_value": "default-src 'self'",
        "reason": "Content-Security-Policy is set with a strong policy",
        "status": "pass"
      },
      "cross-origin-embedder-policy": {
        "present": false,
        "raw_value": null,
        "reason": "Cross-Origin-Embedder-Policy not set",
        "status": "info"
      },
      "cross-origin-opener-policy": {
        "present": false,
        "raw_value": null,
        "reason": "Cross-Origin-Opener-Policy not set",
        "status": "info"
      },
      "cross-origin-resource-policy": {
        "present": false,
        "raw_value": null,
        "reason": "Cross-Origin-Resource-Policy not set",
        "status": "info"
      },
      "permissions-policy": {
        "present": false,
        "raw_value": null,
        "reason": "Permissions-Policy not set — browser features not restricted",
        "status": "warn"
      },
      "referrer-policy": {
        "present": true,
        "raw_value": "strict-origin-when-cross-origin",
        "reason": "Referrer-Policy is set to strict-origin-when-cross-origin",
        "status": "pass"
      },
      "strict-transport-security": {
        "present": true,
        "raw_value": "max-age=31536000; includeSubDomains",
        "reason": "HSTS enabled with max-age=31536000",
        "status": "pass"
      },
      "x-content-type-options": {
        "present": true,
        "raw_value": "nosniff",
        "reason": "X-Content-Type-Options is set to nosniff",
        "status": "pass"
      },
      "x-frame-options": {
        "present": true,
        "raw_value": "DENY",
        "reason": "X-Frame-Options is set to DENY",
        "status": "pass"
      },
      "x-xss-protection": {
        "present": false,
        "raw_value": null,
        "reason": "X-XSS-Protection not set — modern browsers use CSP instead",
        "status": "info"
      }
    },
    "status_code": 200,
    "summary": {
      "fail": 0,
      "info": 4,
      "pass": 6,
      "warn": 0
    }
  },
  "score": 78,
  "service": "security-headers",
  "target": "https://exam

Security scan

  • No findings. We scan names, descriptions and tool definitions for hidden instructions and other prompt-injection patterns.

Recent checks

WhenResultHTTPTimePrice
38 min agoPassed402224 ms$0.01
4 h agoPassed402181 ms$0.01
9 h agoPassed402177 ms$0.01