2s
Fetch a URL and grade its HTTP security headers. Pass url (scheme optional — defaults to https). Returns an overall letter grade + score, the list of present/missing headers, and a per-header analysis with the live value and specific issues for: Strict-Transport-Security (HSTS max-age/includeSubDomains), Content-Security-Policy (flags 'unsafe-inline'/'unsafe-eval'/missing default-src), X-Frame-Options or CSP frame-ancestors (clickjacking), X-Content-Type-Options (nosniff), Referrer-Policy, Permissions-Policy, and Cross-Origin-Opener/Resource-Policy. Also flags Server/X-Powered-By info disclosure. Analyzed from the target's LIVE response headers through an SSRF-guarded fetch (private/loopback targets refused) — an LLM cannot see a site's current headers. For web-app security review, vendor assessment, and CI gates.
Listing completeness · 80/100
Presence of published information only. Not a security, reliability or performance score. Same rules for Datoka and external listings.
- Name and traceable source
- 10/10 · Present
- Meaningful description
- 10/10 · Present
- Connection or installation reference
- 20/20 · Present
- Dedicated documentation or source repository
- 0/15 · Missing or insufficient
- Explicit free access or numeric tariff
- 20/20 · Present
- Declared integration protocol
- 10/10 · Present
- Source updated within 90 days
- 10/10 · Present
- Declared capability names
- 0/5 · Missing or insufficient
Evaluated 2026-10-07 · Method listing-completeness-1. Scoring rules
Connect & use
Connect through the publisher’s supported interface. Any credentials or payments are handled by the provider.
x402 resource
https://2s.io/api/security/http-headersRead the current payment requirements with a compatible client before authorizing a call.
Categories and declared capabilities
Topic categories are derived from publisher text for discovery, not independently verified capabilities.
The registry does not provide a verified tools list. See the observations, when available, for any tools/list check; a published tools list does not establish that execution succeeds.
Evidence, with its limits.
This listing is indexed. Any domain claim or endpoint observation appears separately with its date and limited scope. No payment execution, factual accuracy or safety certification is inferred.