Skip to content

Latest commit

Β 

History

77 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

πŸ”’ HTTP Header Analyzer

Go License: MIT Status

A security-focused HTTP header, TLS, cookie, redirect, and configuration analyzer built with Go.

HTTP Header Analyzer inspects the externally observable security posture of a website and turns its findings into an actionable report. It combines HTTP security-header checks, cookie analysis, TLS inspection, redirect tracking, SSRF-aware URL validation, and a cyberpunk-inspired web interface.

Built for developers, security researchers, penetration testers, system administrators, and security enthusiasts.

Responsible use: Only scan systems that you own or have explicit permission to test.


✨ Features

Area What it does
πŸ›‘οΈ Security headers Checks CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and related controls
πŸͺ Cookie security Reviews Secure, HttpOnly, and SameSite protections
πŸ” TLS inspection Reports protocol, cipher, certificate, issuer, subject, and expiration details
πŸ”€ Redirect analysis Tracks redirect behavior and the final destination
πŸ“Š Security scoring Produces a normalized score from 0–100 with a letter rating
🧠 Remediation Provides explanations and practical recommendations for findings
πŸ›‘ SSRF defenses Rejects localhost, private, loopback, link-local, multicast, and unspecified IP targets
πŸ”Ž Extended analysis Detects technologies, CORS settings, HTTP methods, security.txt, and information disclosure signals
⚑ REST API Supports JSON analysis requests and a health-check endpoint
🎨 Web dashboard Responsive dark/light interface with loading states, notifications, exports, and clipboard tools

πŸ“Έ Screenshots

Dashboard Analysis Findings
Main dashboard Analysis results Detailed findings

Additional analysis


🧭 How it works

Target URL
    β”‚
    β–Ό
Validate URL and apply SSRF protections
    β”‚
    β–Ό
Fetch response and inspect headers, cookies, TLS, and redirects
    β”‚
    β–Ό
Run extended checks and collect evidence
    β”‚
    β–Ό
Calculate score and generate remediation guidance
    β”‚
    β–Ό
Display results in the dashboard or return JSON

πŸ“Š Security rating

The analyzer reports a score between 0 and 100 and maps it to the following rating bands:

Score Rating
97–100 A+
93–96 A
90–92 A-
87–89 B+
83–86 B
80–82 B-
77–79 C+
73–76 C
70–72 C-
60–69 D
0–59 F

⚑ Quick start

Requirements

  • Go 1.21 or newer
  • Git

Install

git clone https://github.com/ItsWanheda/http-header-analyzer.git
cd http-header-analyzer
go mod download

Run the web application

go run ./cmd/server

Then open http://localhost:8080.

Use the CLI

Build the scanner CLI:

go build -o http-header-analyzer ./cmd/http-header-analyzer

Scan a target with human-readable output:

./http-header-analyzer scan https://example.com

Return the complete analysis as machine-readable JSON:

./http-header-analyzer scan https://example.com --json

Save JSON directly to a file:

./http-header-analyzer scan https://example.com --json --output report.json

Control the maximum scan duration:

./http-header-analyzer scan --json --timeout 30s https://example.com

Use quality gates in CI/CD:

# Fail when the score is below 80
./http-header-analyzer scan --min-score 80 https://example.com

# Fail when a High-or-worse issue exists
./http-header-analyzer scan --fail-on high https://example.com

# Combine both checks
./http-header-analyzer scan --json --min-score 80 --fail-on high https://example.com

The CLI exits with a non-zero status when a scan cannot be completed, making it suitable for scripts and CI pipelines.

Build a production binary

go build -o http-header-analyzer ./cmd/server
./http-header-analyzer

On Windows:

go build -o http-header-analyzer.exe ./cmd/server
.\http-header-analyzer.exe

βš™οΈ REST API

Analyze a target

POST /api/analyze
Content-Type: application/json

Request:

{
  "url": "https://example.com"
}

Example response shape:

{
  "url": "https://example.com",
  "score": 95,
  "rating": "A",
  "issues": [
    {
      "header": "Strict-Transport-Security",
      "status": "fail",
      "severity": "High",
      "explanation": "HSTS helps prevent protocol downgrade attacks.",
      "remediation": "Add Strict-Transport-Security with an appropriate max-age."
    }
  ]
}

Health check

GET /api/health
{
  "status": "healthy"
}

πŸ›‘οΈ Security considerations

Because the application makes outbound requests to user-supplied URLs, URL validation is a core security boundary. The validation layer:

  • Accepts only http and https URLs.
  • Rejects embedded credentials and URL fragments.
  • Rejects localhost and local hostnames.
  • Rejects private, loopback, link-local, multicast, and unspecified IP literals.
  • Restricts explicit ports to 80 and 443.
  • Limits request-body sizes and validates JSON API input.

These controls reduce risk but do not replace network-level egress controls, authentication, authorization, or responsible operation. Deploy the service behind appropriate infrastructure controls in production.

See SECURITY.md for reporting security issues.


πŸ—οΈ Project structure

http-header-analyzer/
β”œβ”€β”€ cmd/
β”‚   └── server/
β”‚       └── main.go              # HTTP server and route registration
β”œβ”€β”€ internal/
β”‚   β”œβ”€β”€ analyzer/                # Header, TLS, redirect, and extended analysis
β”‚   β”œβ”€β”€ api/                     # HTTP handlers and JSON responses
β”‚   β”œβ”€β”€ models/                  # Analysis result types
β”‚   └── validation/              # URL and SSRF-aware validation
β”œβ”€β”€ web/
β”‚   β”œβ”€β”€ templates/               # HTML templates
β”‚   └── static/                  # JavaScript and CSS assets
β”œβ”€β”€ assets/                      # Screenshots and project media
β”œβ”€β”€ go.mod
β”œβ”€β”€ go.sum
└── README.md

πŸ§ͺ Development

Format the Go code:

gofmt -w cmd internal

Run the test suite:

go test ./...

Run tests with verbose output:

go test -v ./...

Run static analysis and build all packages:

go vet ./...
go build ./...

🀝 Contributing

Contributions, bug reports, documentation improvements, and security enhancements are welcome.

  1. Fork the repository.
  2. Create a focused branch:
    git checkout -b feature/my-improvement
  3. Make your changes and add tests where appropriate.
  4. Run gofmt, go test ./..., go vet ./..., and go build ./....
  5. Commit using a clear Conventional Commit message.
  6. Push your branch and open a pull request.

Please read CONTRIBUTING.md before submitting changes.

πŸ—ΊοΈ Roadmap

  • JSON analysis reports
  • CSV and PDF report support
  • CSP visualization
  • TLS, cookie, redirect, CORS, and security.txt checks
  • Historical scan tracking
  • Result comparison and regression detection
  • Batch URL scanning
  • Subdomain analysis
  • Expanded CSP policy analysis

πŸ“„ License

This project is distributed under the MIT License.

πŸ‘€ Author

Created and maintained by ItsWanheda.

If you find the project useful, consider giving it a ⭐ and sharing feedback through issues or discussions.


Analyze. Understand. Secure.

Made with ❀️ and Go by ItsWanheda

πŸ”Ž CLI Version

The CLI exposes its current release version without contacting a target:

./http-header-analyzer version
# or
./http-header-analyzer --version

This is useful for verifying the binary installed in a local environment or CI job before running a scan.

About

A powerful, open-source HTTP Header Analyzer built with Go. Features advanced security scanning, TLS inspection, and a stunning Cyberpunk-themed UI.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages