--- name: securityheaders description: HTTP security header audit (A+ to F) with fix recommendations category: security version: 1.0.0 license: Apache-2.0 origin: aiden tags: security, http, headers, csp, hsts, xframe, audit, web, hardening, compliance --- # Security Headers — HTTP Header Audit Check any website for missing or misconfigured HTTP security headers. Returns a grade from A+ to F with a list of which headers are present, which are absent, and why each matters for protection against XSS, clickjacking, MIME sniffing, and data leakage. **No API key required.** Powered by securityheaders.com. ## When to Use - Audit a website before a security review or penetration test - Verify that a newly deployed application has the correct security headers - Check compliance with security baselines (OWASP, NIST, CIS) - User asks "check security headers for X", "is example.com missing HSTS?", "grade the headers on my site" ## How to Use ### Check security headers for a URL ```powershell $target = "https://taracod.com" $encoded = [Uri]::EscapeDataString($target) $url = "https://securityheaders.com/?q=$encoded&followRedirects=on&hide=on" $response = Invoke-WebRequest -Uri $url -UseBasicParsing # Extract grade from HTML badge $grade = if ($response.Content -match 'class="[^"]*reportTitle[^"]*"[^>]*>[\s\S]*?label[^"]*"([^"]+)"') { $Matches[1] -replace 'label[- ]', '' -replace 'success', 'A' -replace 'warning', 'B/C' -replace 'danger', 'D/F' } else { 'check manually' } Write-Host "URL: $target" Write-Host "Grade: $grade" Write-Host "Full report: $url" ``` ### Audit headers and list missing ones ```powershell $target = "https://example.com" $encoded = [Uri]::EscapeDataString($target) $response = Invoke-WebRequest -Uri "https://securityheaders.com/?q=$encoded&followRedirects=on&hide=on" -UseBasicParsing $html = $response.Content # Extract missing headers (rows marked as warnings/missing) $pattern = '