Audit module

Security Headers, CSP & HSTS Checker

What security checks does Audityxe run on a website?

Audityxe reads the live HTTP response and TLS handshake of a URL and checks Content-Security-Policy, HSTS, the other standard security headers, CORS, cookie flags, certificate health, and a few safe read-only server probes — it does not attack or fuzz the site.

Everything on this page is a passive, read-only check of the audited URL. Audityxe is not a penetration-testing tool: it never sends exploit payloads, never tests for XSS or SQL injection, and never reads your source code.

What is checked

Security Headers

Header-level hardening read from the real response.

  • HTTPS and HTTPS→HTTP redirect downgrade
  • Strict-Transport-Security, including max-age, includeSubDomains, and HSTS preload-list eligibility
  • Content-Security-Policy: script-src, style-src, object-src, base-uri, frame-ancestors, and enforcement vs. report-only mode
  • X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy
  • Cross-Origin-Opener-Policy, Cross-Origin-Embedder-Policy, Cross-Origin-Resource-Policy
  • CORS configuration
  • Server header exposure and X-Powered-By
  • Cache-Control on a sensitive path
  • Cookie security and cookie classification
  • Mixed content and form-action security

SSL / TLS Certificate

A live TLS handshake and certificate-chain inspection.

  • Certificate expiration
  • Certificate issuer
  • Hostname / SAN match
  • TLS protocol version
  • Cipher suite
  • Key strength

Server Hardening

Safe, read-only probes.

  • Dangerous HTTP methods
  • Exposed configuration files
  • Directory listing

Subresource Integrity & Link Safety

Third-party asset and link hygiene.

  • Script SRI
  • Stylesheet SRI
  • Public JavaScript source-map exposure
  • target="_blank" tabnabbing risk

Trust Signals

Vulnerability-disclosure readiness.

  • security.txt vulnerability disclosure policy

How to run it

Web app: Paste the URL on the Audityxe homepage and open the Security category in the results.

Command line (see the CLI guide):

npx audityxe-cli https://example.com --min-score 80

Frequently asked questions

Does Audityxe have a Content Security Policy (CSP) analyzer?

Yes. Audityxe evaluates the Content-Security-Policy header of the audited URL, including script-src, style-src, object-src, base-uri, frame-ancestors, and whether the policy is enforced or report-only.

Does Audityxe detect XSS vulnerabilities?

No. Audityxe does not test for cross-site scripting or any injection flaw. It only reads response headers, TLS, DNS, and a few exposed-file probes. A strong CSP reduces XSS impact, but Audityxe cannot tell you whether your application is vulnerable.

Is Audityxe a replacement for OWASP ZAP or a penetration test?

No. Audityxe is a passive configuration and hygiene audit. Use a dynamic scanner such as OWASP ZAP, or a professional penetration test, to look for exploitable vulnerabilities in applications you own.

Last reviewed against the Audityxe source code. Product names mentioned are trademarks of their respective owners; Audityxe is not affiliated with them.