A security-focused HTTP header, TLS, cookie, redirect, and configuration analyzer built with Go.
HTTP Header Analyzer inspects the externally observable security posture of a website and turns its findings into an actionable report. It combines HTTP security-header checks, cookie analysis, TLS inspection, redirect tracking, SSRF-aware URL validation, and a cyberpunk-inspired web interface.
Built for developers, security researchers, penetration testers, system administrators, and security enthusiasts.
Responsible use: Only scan systems that you own or have explicit permission to test.
| Area | What it does |
|---|---|
| π‘οΈ Security headers | Checks CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and related controls |
| πͺ Cookie security | Reviews Secure, HttpOnly, and SameSite protections |
| π TLS inspection | Reports protocol, cipher, certificate, issuer, subject, and expiration details |
| π Redirect analysis | Tracks redirect behavior and the final destination |
| π Security scoring | Produces a normalized score from 0β100 with a letter rating |
| π§ Remediation | Provides explanations and practical recommendations for findings |
| π SSRF defenses | Rejects localhost, private, loopback, link-local, multicast, and unspecified IP targets |
| π Extended analysis | Detects technologies, CORS settings, HTTP methods, security.txt, and information disclosure signals |
| β‘ REST API | Supports JSON analysis requests and a health-check endpoint |
| π¨ Web dashboard | Responsive dark/light interface with loading states, notifications, exports, and clipboard tools |
| Dashboard | Analysis | Findings |
|---|---|---|
![]() |
![]() |
![]() |
Target URL
β
βΌ
Validate URL and apply SSRF protections
β
βΌ
Fetch response and inspect headers, cookies, TLS, and redirects
β
βΌ
Run extended checks and collect evidence
β
βΌ
Calculate score and generate remediation guidance
β
βΌ
Display results in the dashboard or return JSON
The analyzer reports a score between 0 and 100 and maps it to the following rating bands:
| Score | Rating |
|---|---|
| 97β100 | A+ |
| 93β96 | A |
| 90β92 | A- |
| 87β89 | B+ |
| 83β86 | B |
| 80β82 | B- |
| 77β79 | C+ |
| 73β76 | C |
| 70β72 | C- |
| 60β69 | D |
| 0β59 | F |
- Go 1.21 or newer
- Git
git clone https://github.com/ItsWanheda/http-header-analyzer.git
cd http-header-analyzer
go mod downloadgo run ./cmd/serverThen open http://localhost:8080.
Build the scanner CLI:
go build -o http-header-analyzer ./cmd/http-header-analyzerScan a target with human-readable output:
./http-header-analyzer scan https://example.comReturn the complete analysis as machine-readable JSON:
./http-header-analyzer scan https://example.com --jsonSave JSON directly to a file:
./http-header-analyzer scan https://example.com --json --output report.jsonControl the maximum scan duration:
./http-header-analyzer scan --json --timeout 30s https://example.comUse quality gates in CI/CD:
# Fail when the score is below 80
./http-header-analyzer scan --min-score 80 https://example.com
# Fail when a High-or-worse issue exists
./http-header-analyzer scan --fail-on high https://example.com
# Combine both checks
./http-header-analyzer scan --json --min-score 80 --fail-on high https://example.comThe CLI exits with a non-zero status when a scan cannot be completed, making it suitable for scripts and CI pipelines.
go build -o http-header-analyzer ./cmd/server
./http-header-analyzerOn Windows:
go build -o http-header-analyzer.exe ./cmd/server
.\http-header-analyzer.exePOST /api/analyze
Content-Type: application/jsonRequest:
{
"url": "https://example.com"
}Example response shape:
{
"url": "https://example.com",
"score": 95,
"rating": "A",
"issues": [
{
"header": "Strict-Transport-Security",
"status": "fail",
"severity": "High",
"explanation": "HSTS helps prevent protocol downgrade attacks.",
"remediation": "Add Strict-Transport-Security with an appropriate max-age."
}
]
}GET /api/health{
"status": "healthy"
}Because the application makes outbound requests to user-supplied URLs, URL validation is a core security boundary. The validation layer:
- Accepts only
httpandhttpsURLs. - Rejects embedded credentials and URL fragments.
- Rejects localhost and local hostnames.
- Rejects private, loopback, link-local, multicast, and unspecified IP literals.
- Restricts explicit ports to
80and443. - Limits request-body sizes and validates JSON API input.
These controls reduce risk but do not replace network-level egress controls, authentication, authorization, or responsible operation. Deploy the service behind appropriate infrastructure controls in production.
See SECURITY.md for reporting security issues.
http-header-analyzer/
βββ cmd/
β βββ server/
β βββ main.go # HTTP server and route registration
βββ internal/
β βββ analyzer/ # Header, TLS, redirect, and extended analysis
β βββ api/ # HTTP handlers and JSON responses
β βββ models/ # Analysis result types
β βββ validation/ # URL and SSRF-aware validation
βββ web/
β βββ templates/ # HTML templates
β βββ static/ # JavaScript and CSS assets
βββ assets/ # Screenshots and project media
βββ go.mod
βββ go.sum
βββ README.md
Format the Go code:
gofmt -w cmd internalRun the test suite:
go test ./...Run tests with verbose output:
go test -v ./...Run static analysis and build all packages:
go vet ./...
go build ./...Contributions, bug reports, documentation improvements, and security enhancements are welcome.
- Fork the repository.
- Create a focused branch:
git checkout -b feature/my-improvement
- Make your changes and add tests where appropriate.
- Run
gofmt,go test ./...,go vet ./..., andgo build ./.... - Commit using a clear Conventional Commit message.
- Push your branch and open a pull request.
Please read CONTRIBUTING.md before submitting changes.
- JSON analysis reports
- CSV and PDF report support
- CSP visualization
- TLS, cookie, redirect, CORS, and
security.txtchecks - Historical scan tracking
- Result comparison and regression detection
- Batch URL scanning
- Subdomain analysis
- Expanded CSP policy analysis
This project is distributed under the MIT License.
Created and maintained by ItsWanheda.
If you find the project useful, consider giving it a β and sharing feedback through issues or discussions.
Analyze. Understand. Secure.
Made with β€οΈ and Go by ItsWanheda
The CLI exposes its current release version without contacting a target:
./http-header-analyzer version
# or
./http-header-analyzer --versionThis is useful for verifying the binary installed in a local environment or CI job before running a scan.



