Repository navigation
Home
A security-focused HTTP header analyzer written in Go, with TLS inspection, security scoring, SSRF protection, a REST API, and a cyberpunk web dashboard.
http-header-analyzer analyzes HTTP/HTTPS targets and identifies security-related configuration issues.
It evaluates areas such as:
- π Security headers
- πͺ Cookie security
- π TLS configuration
- βͺοΈ Redirect behavior
- π CORS configuration
- π‘οΈ SSRF-sensitive target handling
- π‘ HTTP methods
- π Technology disclosure
- π
security.txt - π¨ Information disclosure
- π Security scoring and ratings
The project is designed for security researchers, developers, penetration testers, and anyone who wants a quick security-oriented view of an HTTP endpoint.
Analyze commonly used HTTP security controls including:
- Content Security Policy
- Strict-Transport-Security
- X-Content-Type-Options
- X-Frame-Options
- Cookie security attributes
- CORS configuration
- HTTP method exposure
Inspect HTTPS configuration and certificate information, including:
- TLS version
- Certificate metadata
- Certificate validity
- Handshake information
- Weak or potentially insecure configurations
The analyzer includes defensive URL and network validation to reduce the risk of scanning internal or reserved network targets.
Protection covers areas such as:
- Loopback addresses
- Private IPv4 ranges
- Private IPv6 ranges
- Link-local addresses
- Multicast and unspecified addresses
- Unsafe redirect targets
- Restricted URL forms
Scan results are converted into a security score and rating to make findings easier to understand and integrate into automated workflows.
The project provides a command-line interface for automated and manual scanning.
Example:
./http-header-analyzer scan https://example.comJSON output:
./http-header-analyzer scan --json https://example.comQuality gates:
./http-header-analyzer scan --min-score 80 https://example.com
./http-header-analyzer scan --fail-on high https://example.comThe project also provides an HTTP API for integrating analysis into other applications and security workflows.
The project is organized around several main components:
http-header-analyzer/
βββ cmd/
β βββ http-header-analyzer/
β βββ server/
β
βββ internal/
β βββ analyzer/
β βββ api/
β βββ models/
β βββ validation/
β
βββ web/
β
βββ tests/
β
βββ .github/
β βββ workflows/
β
βββ CHANGELOG.md
βββ CONTRIBUTING.md
βββ SECURITY.md
βββ README.md
Target URL
β
βΌ
URL Validation
β
βΌ
Safe Network Connection
β
βΌ
HTTP Request
β
βββ Headers
βββ Cookies
βββ TLS
βββ Redirects
βββ CORS
βββ Methods
βββ Other Analysis
β
βΌ
Security Rules
β
βΌ
Score & Findings
β
βββ CLI
βββ JSON
βββ REST API
βββ Web Dashboard
Requirements:
- Go 1.21+
- Git
Run tests:
go test ./...Run static analysis:
go vet ./...Build the project:
go build ./...Run the server:
go run ./cmd/serverThe repository uses GitHub Actions for automated verification.
Current automation includes:
- π§ͺ Go tests
- π
go vet - ποΈ Go builds
- π‘οΈ CodeQL security analysis
- π€ Dependabot dependency updates
The CodeQL workflow analyzes Go code on pull requests, pushes to main, and scheduled security scans.
Useful documentation:
- README β Project overview and quick start
- CHANGELOG β Version history and development milestones
- CONTRIBUTING β Contribution and development guidelines
- SECURITY β Security vulnerability reporting policy
Additional wiki pages can cover individual components in greater depth.
The current development roadmap focuses on:
- π‘οΈ Expanded security regression testing
- π Improved TLS analysis
- β‘ Extended CLI capabilities
- π¦ Automated releases
- π Improved API documentation
- π Additional security tooling
Contributions are welcome.
Before submitting a pull request:
go test ./...
go vet ./...
go build ./...For security vulnerabilities, please follow the project's security reporting process rather than opening a public issue.
See the repository's LICENSE file for licensing information.
http-header-analyzer β inspect deeper. Secure smarter. π‘οΈ