Security headers
Bulk OWASP security-header audits for HSTS, CSP, and grades
This Actor requests the URLs you supply, reads HTTP response headers, and scores them against OWASP-oriented directives such as HSTS and CSP. Maximum 200 URLs per run.
Not a penetration test, fuzzer, or authenticated scan. Passive header inspection only; only scan sites you are authorized to check.
from $7.00 / 1,000 results ($0.007 per result) plus Actor Start $0.001.
Open Security Headers Checker on Apify
Security Headers Checker, not a neighboring Actor
Use this page for this Actor’s job. Use SSL/TLS Certificate Scraper for TLS cert expiry and fingerprints; Use DMARC & Email Security Checker for DMARC/SPF/DKIM DNS; Use Bulk URL Status Checker for HTTP status on a known list.
| This Actor | SSL/TLS Certificate Scraper | DMARC & Email Security Checker | Bulk URL Status Checker | |
|---|---|---|---|---|
| Intent | Security Headers Checker | TLS cert expiry and fingerprints | DMARC/SPF/DKIM DNS | HTTP status on a known list |
| Primary input | urls |
domains (max 200) | domains | urls (max 1000) |
| What it reads | Public sources listed on the Store page | TLS handshake, not HTTP headers | DNS TXT | HTTP status/redirects |
| Primary output | Dataset rows billed per live PPE | cert rows | email-auth rows | status rows |
| Not this job | Not a penetration test, fuzzer, or authenticated scan. Passive header inspection only; only scan sites you are authorized to check. | Not OWASP header grades | Not HTTP security headers | Not header-policy scoring |
Store ID: taroyamada/security-headers-checker. Respect source terms, robots.txt, and rate limits.
Use cases
- Bulk header compliance grades
- Missing HSTS/CSP detection
- Recurring snapshot comparison via snapshotKey
How is Security Headers Checker different from SSL/TLS Certificate Scraper and DMARC & Email Security Checker?
Security Headers Checker — OWASP HSTS CSP Bulk Audit (taroyamada/security-headers-checker): This Actor requests the URLs you supply, reads HTTP response headers, and scores them against OWASP-oriented directives such as HSTS and CSP. Maximum 200 URLs per run. Not a penetration test, fuzzer, or authenticated scan. Passive header inspection only; only scan sites you are authorized to check. SSL/TLS Certificate Scraper is for TLS cert expiry and fingerprints (input domains (max 200); TLS handshake, not HTTP headers; cert rows). Not OWASP header grades. DMARC & Email Security Checker is for DMARC/SPF/DKIM DNS (input domains; DNS TXT; email-auth rows). Not HTTP security headers. Bulk URL Status Checker is for HTTP status on a known list (input urls (max 1000); HTTP status/redirects; status rows). Not header-policy scoring.
What input is required?
Live required fields: urls. exampleRunInput audits google.com, github.com, cloudflare.com with concurrency 3. Schema prefill uses example.com as the third URL and concurrency default 5. Max 200 URLs.
| Field | Type | Default | Notes |
|---|---|---|---|
urls |
array required | empty |
URLs to Check. List of URLs to audit security headers for. Maximum 200 per run. |
followRedirects |
boolean | true |
Follow Redirects. Follow HTTP redirects and check the final URL's headers. |
delivery |
string | dataset |
Delivery Mode. How to deliver results. 'dataset' saves to Apify Dataset (recommended), 'webhook' sends to a URL. |
webhookUrl |
string | empty |
Webhook URL. Webhook URL to send results to (only used when delivery is 'webhook'). Works with Slack, Discord, or any HTTP endpoint. |
snapshotKey |
string | security-headers-snapshots |
Snapshot Key. Key name for storing snapshots (used for change detection between runs). |
concurrency |
integer | 5 |
Concurrency. Maximum number of parallel requests. Higher = faster but may trigger rate limits. |
dryRun |
boolean | false |
Dry Run. If true, runs without saving results or sending webhooks. Useful for testing. |
Published Store example run input (omitted fields take schema defaults):
{
"urls": [
"https://google.com",
"https://github.com",
"https://cloudflare.com"
],
"followRedirects": true,
"concurrency": 3,
"delivery": "dataset",
"snapshotKey": "security-headers-snapshots",
"dryRun": false
}
Run Security Headers Checker on Apify
How do dataset, webhook, and dry-run delivery work?
delivery defaults to dataset on the live schema. Dataset output is the billable surface when rows are written. webhookUrl is used when delivery is webhook (and typically not during dryRun). dryRun true validates or samples without the usual dataset/webhook side effects described on the Store schema.
What does a result contain?
Published README Output Example / Sample Output JSON.
{
"url": "https://github.com",
"score": {
"total": 75,
"grade": "B",
"details": [
{
"header": "strict-transport-security",
"status": "pass",
"points": 20
},
{
"header": "content-security-policy",
"status": "missing",
"points": 0,
"note": "Missing. Add a Content-Security-Policy header"
}
]
},
"statusCode": 200,
"headers": {
"strict-transport-security": "max-age=31536000; includeSubdomains; preload",
"x-frame-options": "deny",
"x-content-type-options": "nosniff"
}
}
There is no published output JSON schema on the Store page.
How is Security Headers Checker priced?
Billing is pay per event. The live Store card is from $7.00 / 1,000 results ($0.007 per result) plus Actor Start $0.001. Current PPE:
| Event | Price | Emitted when |
|---|---|---|
apify-actor-start (Actor Start) |
$0.001 | Charged when the Actor starts running. Number of events charged depends on Actor memory (one event per GB, minimum one event). |
apify-default-dataset-item (result) |
$0.007 | Single result in the default dataset. |
The published README Cost block is stale versus the live Store pricing tab. README Cost quotes actor-start $0.01 + dataset-item $0.003. Live: Actor Start $0.001 + result $0.007. This page quotes live PPE only.
from $7.00 / 1,000 results ($0.007 per result) plus Actor Start $0.001.
See Security Headers Checker pricing on Apify
Limits to keep in mind
- Max 200 URLs
- concurrency 1–10
- No exploitation or auth bypass
- Authorization required for third-party sites
- Respect source terms, robots.txt, and rate limits.
Open Security Headers Checker on Apify
Related pages
- SSL/TLS Certificate Scraper — Certificate expiry, not CSP/HSTS grades.
- DMARC & Email Security Checker — Email DNS posture, not HTTP headers.
- Bulk URL Status Checker — Status codes on a URL list, not OWASP header audits.
- Domain Trust Reputation Scraper — SSL + DMARC + headers executive summary
- Tools