HTTP Header Security Analyser
Score HTTP security headers against OWASP best practices.
Security ToolsRuns on our server · input is not storedNo account · No API key
Try it
Result
Call it from an agent
The same endpoint powers the form above. Send JSON, get JSON — no key, no signup.
curl -sX POST 'https://itsfully.online/backend/connector-api.php?action=execute' \
-H 'Content-Type: application/json' \
-d '{"tool":"http-header-security-analyser","data":{ /* see input fields above */ }}'
Input schema
Parameters accepted by this tool:
[
{
"type": "text",
"name": "url",
"label": "URL to Analyse",
"placeholder": "https://example.com",
"hint": "Fetches headers via HTTP request."
},
{
"type": "textarea",
"name": "raw_headers",
"label": "Or paste raw HTTP headers",
"rows": 8,
"placeholder": "Strict-Transport-Security: max-age=31536000\nContent-Security-Policy: default-src 'self'"
}
]