Skip to content
ItsWanheda edited this page Sep 24, 2026 · 1 revision

πŸ›‘οΈ HTTP Header Analyzer

A security-focused HTTP header analyzer written in Go, with TLS inspection, security scoring, SSRF protection, a REST API, and a cyberpunk web dashboard.


πŸš€ Overview

http-header-analyzer analyzes HTTP/HTTPS targets and identifies security-related configuration issues.

It evaluates areas such as:

  • πŸ” Security headers
  • πŸͺ Cookie security
  • πŸ”’ TLS configuration
  • β†ͺ️ Redirect behavior
  • 🌐 CORS configuration
  • πŸ›‘οΈ SSRF-sensitive target handling
  • πŸ“‘ HTTP methods
  • πŸ”Ž Technology disclosure
  • πŸ“„ security.txt
  • 🚨 Information disclosure
  • πŸ“Š Security scoring and ratings

The project is designed for security researchers, developers, penetration testers, and anyone who wants a quick security-oriented view of an HTTP endpoint.


✨ Features

Security Analysis

Analyze commonly used HTTP security controls including:

  • Content Security Policy
  • Strict-Transport-Security
  • X-Content-Type-Options
  • X-Frame-Options
  • Cookie security attributes
  • CORS configuration
  • HTTP method exposure

πŸ”’ TLS Inspection

Inspect HTTPS configuration and certificate information, including:

  • TLS version
  • Certificate metadata
  • Certificate validity
  • Handshake information
  • Weak or potentially insecure configurations

πŸ›‘οΈ SSRF Protection

The analyzer includes defensive URL and network validation to reduce the risk of scanning internal or reserved network targets.

Protection covers areas such as:

  • Loopback addresses
  • Private IPv4 ranges
  • Private IPv6 ranges
  • Link-local addresses
  • Multicast and unspecified addresses
  • Unsafe redirect targets
  • Restricted URL forms

πŸ“Š Security Scoring

Scan results are converted into a security score and rating to make findings easier to understand and integrate into automated workflows.

πŸ’» CLI

The project provides a command-line interface for automated and manual scanning.

Example:

./http-header-analyzer scan https://example.com

JSON output:

./http-header-analyzer scan --json https://example.com

Quality gates:

./http-header-analyzer scan --min-score 80 https://example.com
./http-header-analyzer scan --fail-on high https://example.com

🌐 REST API

The project also provides an HTTP API for integrating analysis into other applications and security workflows.


πŸ—οΈ Architecture

The project is organized around several main components:

http-header-analyzer/
β”œβ”€β”€ cmd/
β”‚   β”œβ”€β”€ http-header-analyzer/
β”‚   └── server/
β”‚
β”œβ”€β”€ internal/
β”‚   β”œβ”€β”€ analyzer/
β”‚   β”œβ”€β”€ api/
β”‚   β”œβ”€β”€ models/
β”‚   └── validation/
β”‚
β”œβ”€β”€ web/
β”‚
β”œβ”€β”€ tests/
β”‚
β”œβ”€β”€ .github/
β”‚   └── workflows/
β”‚
β”œβ”€β”€ CHANGELOG.md
β”œβ”€β”€ CONTRIBUTING.md
β”œβ”€β”€ SECURITY.md
└── README.md

Core flow

Target URL
    β”‚
    β–Ό
URL Validation
    β”‚
    β–Ό
Safe Network Connection
    β”‚
    β–Ό
HTTP Request
    β”‚
    β”œβ”€β”€ Headers
    β”œβ”€β”€ Cookies
    β”œβ”€β”€ TLS
    β”œβ”€β”€ Redirects
    β”œβ”€β”€ CORS
    β”œβ”€β”€ Methods
    └── Other Analysis
    β”‚
    β–Ό
Security Rules
    β”‚
    β–Ό
Score & Findings
    β”‚
    β”œβ”€β”€ CLI
    β”œβ”€β”€ JSON
    β”œβ”€β”€ REST API
    └── Web Dashboard

πŸ§ͺ Development

Requirements:

  • Go 1.21+
  • Git

Run tests:

go test ./...

Run static analysis:

go vet ./...

Build the project:

go build ./...

Run the server:

go run ./cmd/server

πŸ”„ CI & Security

The repository uses GitHub Actions for automated verification.

Current automation includes:

  • πŸ§ͺ Go tests
  • πŸ” go vet
  • πŸ—οΈ Go builds
  • πŸ›‘οΈ CodeQL security analysis
  • πŸ€– Dependabot dependency updates

The CodeQL workflow analyzes Go code on pull requests, pushes to main, and scheduled security scans.


πŸ“š Documentation

Useful documentation:

  • README β€” Project overview and quick start
  • CHANGELOG β€” Version history and development milestones
  • CONTRIBUTING β€” Contribution and development guidelines
  • SECURITY β€” Security vulnerability reporting policy

Additional wiki pages can cover individual components in greater depth.


πŸ—ΊοΈ Roadmap

The current development roadmap focuses on:

  • πŸ›‘οΈ Expanded security regression testing
  • πŸ”’ Improved TLS analysis
  • ⚑ Extended CLI capabilities
  • πŸ“¦ Automated releases
  • πŸ“š Improved API documentation
  • πŸ” Additional security tooling

🀝 Contributing

Contributions are welcome.

Before submitting a pull request:

go test ./...
go vet ./...
go build ./...

For security vulnerabilities, please follow the project's security reporting process rather than opening a public issue.


πŸ“„ License

See the repository's LICENSE file for licensing information.


http-header-analyzer β€” inspect deeper. Secure smarter. πŸ›‘οΈ