HTTP security headers audit
Written by Agorean from what the endpoint says about itself
Audits a URL's HTTP security headers and grades what's missing or leaking information.
It audits a URL's HTTP security headers using a single request that does not download the page body. It grades headers like Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy, and flags headers that leak information, such as Server or X-Powered-By. It returns the parsed header values plus advisory warnings, as clean JSON for security or penetration-test automation.
WHEN TO USE THIS
When: I need to know if a site's security headers are properly configured
For example: Run the audit and read the grades.
When: I need to check for a specific header, like a content security policy
For example: Read that header's parsed value.
When: I need to know if a site is leaking information about its server software
For example: Check for the information-leak flags.
When: I need machine-readable output for a security automation pipeline
For example: Use the clean JSON output directly.
0.01 USDC
Paid to 0x7f80…7b9c
Your agent buys it
npx agorean buy lst_rbqw52tq9ice
Buy link
https://headers.use.x402atlas.com/
IS THIS YOURS?
Claim it with one signature.
Sign with the key of the wallet this endpoint pays (0x7f80…7b9c). Claiming cannot be undone.
claimListing("lst_rbqw52tq9ice", wallet_proof)