# Security Headers Checker (`s3nafps/security-headers-checker`) Actor

Check public URLs for common HTTP security headers including HSTS, Content Security Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy. Export a simple website security header report as JSON or CSV.

- **URL**: https://apify.com/s3nafps/security-headers-checker.md
- **Developed by:** [mohamed senator](https://apify.com/s3nafps) (community)
- **Categories:** Developer tools, SEO tools
- **Stats:** 2 total users, 1 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

$0.50 / 1,000 checked urls

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.

Learn more: https://docs.apify.com/platform/actors/running/actors-in-store#pay-per-event

## What's an Apify Actor?

Actors are web data automations that power AI and operations. They run on the Apify platform to scrape websites, process data, connect APIs, and automate workflows.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.
Actors are written with capital "A".

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.
The best way to integrate Actors is as follows.

- **AI agents and MCP clients** — the [Apify MCP server](https://docs.apify.com/integrations/mcp.md) at `https://mcp.apify.com` (remote, streamable HTTP, OAuth on first use).
- **Agentic workflows and local Actor development** — [Agent Skills](https://apify.com/.well-known/agent-skills/index.json) with the [Apify CLI](https://docs.apify.com/cli/docs.md): `npm install -g apify-cli`, then `apify login`.
- **JavaScript/TypeScript projects** — the official [JS/TS client](https://docs.apify.com/api/client/js/docs.md): `npm install apify-client`.
- **Python projects** — the official [Python client](https://docs.apify.com/api/client/python/docs.md): `pip install apify-client`.
- **Any other language** — the [REST API](https://docs.apify.com/api/v2.md).

For usage examples, see the [API](#api) section below.

For more details, see Apify documentation as [Markdown index](https://docs.apify.com/llms.txt) and [Markdown full-text](https://docs.apify.com/llms-full.txt).

# README

## Security Headers Checker

Audit public URLs for common HTTP security headers. This Apify Actor checks whether each URL uses HTTPS and whether the final response includes headers such as HSTS, Content Security Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy.

### What does this Actor do?

Security Headers Checker helps website owners, agencies, developers, and no-code operators run quick security-header QA checks across a list of public URLs. It is useful before launches, after migrations, or as a recurring lightweight website health check.

The Actor uses only public URLs that you provide. It does not log in, bypass CAPTCHA, scan private networks, exploit vulnerabilities, or perform penetration testing.

### Typical use cases

- Check client websites for missing security headers
- Verify HTTPS and HSTS after a migration
- Audit landing pages before a campaign launch
- Export a simple security header report to CSV or JSON
- Monitor important public URLs on a schedule

### Input

Add public `http://` or `https://` URLs. Local, private-network, malformed, FTP, and non-HTTP URLs are rejected.

```json
{
  "startUrls": [
    { "url": "https://example.com" },
    { "url": "https://www.iana.org" }
  ],
  "maxResults": 100,
  "requestTimeoutSecs": 20
}
```

### Output

Each checked URL is saved as one item in the Apify Dataset.

| Field | Meaning |
|---|---|
| `originalUrl` | URL you provided |
| `finalUrl` | Final URL after redirects |
| `statusCode` | Final HTTP status code |
| `ok` | `true` for successful 2xx/3xx final status without request error |
| `usesHttps` | Whether the final URL uses HTTPS |
| `strictTransportSecurity` | Value of `Strict-Transport-Security` if present |
| `contentSecurityPolicy` | Value of `Content-Security-Policy` if present |
| `xFrameOptions` | Value of `X-Frame-Options` if present |
| `xContentTypeOptions` | Value of `X-Content-Type-Options` if present |
| `referrerPolicy` | Value of `Referrer-Policy` if present |
| `permissionsPolicy` | Value of `Permissions-Policy` if present |
| `missingHeaders` | Common security headers not found |
| `score` | Simple 0–100 score based on present headers |
| `error` | Clear error message if the URL could not be checked |
| `checkedAt` | ISO timestamp of the check |

### Example output

```json
{
  "originalUrl": "https://example.com/",
  "finalUrl": "https://example.com/",
  "statusCode": 200,
  "ok": true,
  "usesHttps": true,
  "strictTransportSecurity": null,
  "contentSecurityPolicy": null,
  "xFrameOptions": null,
  "xContentTypeOptions": "nosniff",
  "referrerPolicy": null,
  "permissionsPolicy": null,
  "missingHeaders": ["strict-transport-security", "content-security-policy"],
  "score": 17,
  "error": null,
  "checkedAt": "2026-07-04T00:00:00.000Z"
}
```

### Limitations

- This Actor checks public response headers only.
- It is not a penetration test, vulnerability scanner, or compliance certification tool.
- Some websites block automated requests; those URLs will return an error instead of fake success.
- Header presence does not guarantee that a policy is strong or correctly configured.

### Suggested Pay Per Event pricing

Recommended primary event: one checked URL / default dataset item.

Suggested launch price: **$0.50 per 1,000 checked URLs** plus Apify platform usage costs.

### SEO title suggestion

Security Headers Checker API - Bulk HTTP Header Audit

### SEO description suggestion

Check public URLs for common HTTP security headers including HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy.

# Actor input Schema

## `startUrls` (type: `array`):

Public website URLs to check for common HTTP security headers.

## `maxResults` (type: `integer`):

Stops after this many unique input URLs.

## `requestTimeoutSecs` (type: `integer`):

How long to wait for each URL before recording an error.

## Actor input object example

```json
{
  "startUrls": [
    {
      "url": "https://example.com"
    },
    {
      "url": "https://www.iana.org"
    },
    {
      "url": "https://docs.apify.com"
    }
  ],
  "maxResults": 3,
  "requestTimeoutSecs": 20
}
```

# Actor output Schema

## `results` (type: `string`):

Open the default dataset in Apify Console. The dataset schema selects a clean table view with the most useful fields first.

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {
    "startUrls": [
        {
            "url": "https://example.com"
        },
        {
            "url": "https://www.iana.org"
        },
        {
            "url": "https://docs.apify.com"
        }
    ],
    "maxResults": 3,
    "requestTimeoutSecs": 20
};

// Run the Actor and wait for it to finish
const run = await client.actor("s3nafps/security-headers-checker").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = {
    "startUrls": [
        { "url": "https://example.com" },
        { "url": "https://www.iana.org" },
        { "url": "https://docs.apify.com" },
    ],
    "maxResults": 3,
    "requestTimeoutSecs": 20,
}

# Run the Actor and wait for it to finish
run = client.actor("s3nafps/security-headers-checker").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print("💾 Check your data here: https://console.apify.com/storage/datasets/" + run["defaultDatasetId"])
for item in client.dataset(run["defaultDatasetId"]).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{
  "startUrls": [
    {
      "url": "https://example.com"
    },
    {
      "url": "https://www.iana.org"
    },
    {
      "url": "https://docs.apify.com"
    }
  ],
  "maxResults": 3,
  "requestTimeoutSecs": 20
}' |
apify call s3nafps/security-headers-checker --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "command": "npx",
            "args": [
                "mcp-remote",
                "https://mcp.apify.com/?tools=s3nafps/security-headers-checker",
                "--header",
                "Authorization: Bearer <YOUR_API_TOKEN>"
            ]
        }
    }
}

```

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/actors/MhIpCKkiesw1r4sgv/builds/Kf8atk8ddAqvviU5n/openapi.json
