Security headers

Bulk OWASP security-header audits for HSTS, CSP, and grades

This Actor requests the URLs you supply, reads HTTP response headers, and scores them against OWASP-oriented directives such as HSTS and CSP. Maximum 200 URLs per run.

Not a penetration test, fuzzer, or authenticated scan. Passive header inspection only; only scan sites you are authorized to check.

from $7.00 / 1,000 results ($0.007 per result) plus Actor Start $0.001.

Open Security Headers Checker on Apify

Security Headers Checker, not a neighboring Actor

Use this page for this Actor’s job. Use SSL/TLS Certificate Scraper for TLS cert expiry and fingerprints; Use DMARC & Email Security Checker for DMARC/SPF/DKIM DNS; Use Bulk URL Status Checker for HTTP status on a known list.

This Actor SSL/TLS Certificate Scraper DMARC & Email Security Checker Bulk URL Status Checker
Intent Security Headers Checker TLS cert expiry and fingerprints DMARC/SPF/DKIM DNS HTTP status on a known list
Primary input urls domains (max 200) domains urls (max 1000)
What it reads Public sources listed on the Store page TLS handshake, not HTTP headers DNS TXT HTTP status/redirects
Primary output Dataset rows billed per live PPE cert rows email-auth rows status rows
Not this job Not a penetration test, fuzzer, or authenticated scan. Passive header inspection only; only scan sites you are authorized to check. Not OWASP header grades Not HTTP security headers Not header-policy scoring

Store ID: taroyamada/security-headers-checker. Respect source terms, robots.txt, and rate limits.

Use cases

How is Security Headers Checker different from SSL/TLS Certificate Scraper and DMARC & Email Security Checker?

Security Headers Checker — OWASP HSTS CSP Bulk Audit (taroyamada/security-headers-checker): This Actor requests the URLs you supply, reads HTTP response headers, and scores them against OWASP-oriented directives such as HSTS and CSP. Maximum 200 URLs per run. Not a penetration test, fuzzer, or authenticated scan. Passive header inspection only; only scan sites you are authorized to check. SSL/TLS Certificate Scraper is for TLS cert expiry and fingerprints (input domains (max 200); TLS handshake, not HTTP headers; cert rows). Not OWASP header grades. DMARC & Email Security Checker is for DMARC/SPF/DKIM DNS (input domains; DNS TXT; email-auth rows). Not HTTP security headers. Bulk URL Status Checker is for HTTP status on a known list (input urls (max 1000); HTTP status/redirects; status rows). Not header-policy scoring.

What input is required?

Live required fields: urls. exampleRunInput audits google.com, github.com, cloudflare.com with concurrency 3. Schema prefill uses example.com as the third URL and concurrency default 5. Max 200 URLs.

Field Type Default Notes
urls array required empty URLs to Check. List of URLs to audit security headers for. Maximum 200 per run.
followRedirects boolean true Follow Redirects. Follow HTTP redirects and check the final URL's headers.
delivery string dataset Delivery Mode. How to deliver results. 'dataset' saves to Apify Dataset (recommended), 'webhook' sends to a URL.
webhookUrl string empty Webhook URL. Webhook URL to send results to (only used when delivery is 'webhook'). Works with Slack, Discord, or any HTTP endpoint.
snapshotKey string security-headers-snapshots Snapshot Key. Key name for storing snapshots (used for change detection between runs).
concurrency integer 5 Concurrency. Maximum number of parallel requests. Higher = faster but may trigger rate limits.
dryRun boolean false Dry Run. If true, runs without saving results or sending webhooks. Useful for testing.

Published Store example run input (omitted fields take schema defaults):

{
  "urls": [
    "https://google.com",
    "https://github.com",
    "https://cloudflare.com"
  ],
  "followRedirects": true,
  "concurrency": 3,
  "delivery": "dataset",
  "snapshotKey": "security-headers-snapshots",
  "dryRun": false
}

Run Security Headers Checker on Apify

How do dataset, webhook, and dry-run delivery work?

delivery defaults to dataset on the live schema. Dataset output is the billable surface when rows are written. webhookUrl is used when delivery is webhook (and typically not during dryRun). dryRun true validates or samples without the usual dataset/webhook side effects described on the Store schema.

What does a result contain?

Published README Output Example / Sample Output JSON.

{
  "url": "https://github.com",
  "score": {
    "total": 75,
    "grade": "B",
    "details": [
      {
        "header": "strict-transport-security",
        "status": "pass",
        "points": 20
      },
      {
        "header": "content-security-policy",
        "status": "missing",
        "points": 0,
        "note": "Missing. Add a Content-Security-Policy header"
      }
    ]
  },
  "statusCode": 200,
  "headers": {
    "strict-transport-security": "max-age=31536000; includeSubdomains; preload",
    "x-frame-options": "deny",
    "x-content-type-options": "nosniff"
  }
}

There is no published output JSON schema on the Store page.

How is Security Headers Checker priced?

Billing is pay per event. The live Store card is from $7.00 / 1,000 results ($0.007 per result) plus Actor Start $0.001. Current PPE:

Event Price Emitted when
apify-actor-start (Actor Start) $0.001 Charged when the Actor starts running. Number of events charged depends on Actor memory (one event per GB, minimum one event).
apify-default-dataset-item (result) $0.007 Single result in the default dataset.

The published README Cost block is stale versus the live Store pricing tab. README Cost quotes actor-start $0.01 + dataset-item $0.003. Live: Actor Start $0.001 + result $0.007. This page quotes live PPE only.

from $7.00 / 1,000 results ($0.007 per result) plus Actor Start $0.001.

See Security Headers Checker pricing on Apify

Limits to keep in mind

Open Security Headers Checker on Apify

Related pages