Content-Security-Policy built from the app shell you serve: inline-script hashes, per-response nonces and presets.
-
Updated
Oct 7, 2026 - Rust
Content-Security-Policy built from the app shell you serve: inline-script hashes, per-response nonces and presets.
Leitura diária e passiva da superfície pública de alvos declarados — cabeçalhos, TLS, DNS e Transparência de Certificados — como série temporal. Inconclusivo não é ausência.
Scan web assets for exploitable vulnerabilities using real-time data from CISA KEV and the National Vulnerability Database.
Zero-dependency security SDK for Node.js & TypeScript — verified webhooks (GitHub, Stripe, Slack, Standard Webhooks), CSRF & request policy, CORS, secure headers, SSRF-safe fetch, rate limiting, idempotency keys, secret redaction and a secret scanner with SARIF
Stamp configurable baseline security headers (CSP, HSTS, COOP, Permissions-Policy) via a single middleware.
Portfolio y blog trilingüe (ES/EN/CA) de Eduardo Olivares, analista SOC. Astro estático + API propia en PHP/MySQL con panel de administración. CSP con hashes por build, analítica sin cookies y SEO estructurado.
Composable server-side HTTP middleware with explicit ordering and transport-safe behavior.
Developer-first Chromium extension for real-time API sniffing, OWASP security header auditing, and 1-click cURL/RestPocket exports.
Scanner de vulnerabilidades web. XSS reflejado, SQL injection, auditoría de headers de seguridad, enumeración de subdominios y recolección de URLs históricas via Wayback Machine.
Harden your Go net/http server with logging, security headers, safe client IPs and graceful shutdown
A lightweight CLI tool that fetches a URL's HTTP response headers and scores them against common web security best practices (similar in spirit to securityheaders.com, but self-hosted and offline-f...
Self-hostable scanner for TLS configuration and HTTP security headers. Single Go binary, embedded UI.
🛡️ Enhance your ASP.NET Core projects with default security headers using ByteGuard.SecurityHeaders for a safer web experience.
HeaderGuard — get alerted when your HTTP security headers change
Static multi-page portfolio on Cloudflare Workers Static Assets, with a Turnstile-protected contact Worker, strict security headers, and evidence-calibrated project claims.
🔒 CLI tool for analyzing website security headers. Checks 15+ security headers, provides detailed reports, and exports to TXT/JSON/CSV. Perfect for security audits and compliance checks.
Screenshot and recon web targets into one rich, self-contained HTML report (TLS, security headers, tech fingerprint). Native on Apple Silicon, no Docker or Selenium.
A PowerShell tool for inspecting HTTP security headers, redirects, and response details.
Web security posture auditor: HTTPS/HSTS, deep CSP analysis, clickjacking, cookie flags, CORS, version leaks and TLS certificate checks, graded A+ to F with fixes and HTML reports.
Website security posture scanner: TLS, headers, CSP, cookies, CORS, exposed files and DNS, graded A+ to F — with a CLI and a React console.
To associate your repository with the security-headers topic, visit your repo's landing page and select "manage topics."