2s.io
Fetch a URL and grade its HTTP security headers. Pass url (scheme optional — defaults to https). Returns an overall letter grade + score, the list of present/missing headers, and a per-header analysis with the live value and specific issues for: Strict-Transport-Security (HSTS max-age/includeSubDomains), Content-Security-Policy (flags 'unsafe-inline'/'unsafe-eval'/missing default-src), X-Frame-Options or CSP frame-ancestors (clickjacking), X-Content-Type-Options (nosniff), Referrer-Policy, Permissions-Policy, and Cross-Origin-Opener/Resource-Policy. Also flags Server/X-Powered-By info disclosure. Analyzed from the target's LIVE response headers through an SSRF-guarded fetch (private/loopback targets refused) — an LLM cannot see a site's current headers. For web-app security review, vendor assessment, and CI gates.
Resource URL
https://2s.io/api/security/http-headers
Payment options
$0.0045 USDC
Max amount
- Pay to
- 0x2b6D4988Db4723E6908Db86Ab2b8dFBc51FC32C5
- Timeout
- 60s
$0.0045 USDC
Max amount
- Pay to
- TW6ntaGzvj63ZgPjszd4FCGmVTGfzv1MAYZbjYcyWhn
- Timeout
- 60s
Tags
For agents
Prompt snippet for AI agents
Find and pay for this x402 resource: URL: https://2s.io/api/security/http-headers Type: http Sources: cdp, thirdweb, ultravioletadao