Audit module
Security Headers, CSP & HSTS Checker
What security checks does Audityxe run on a website?
Audityxe reads the live HTTP response and TLS handshake of a URL and checks Content-Security-Policy, HSTS, the other standard security headers, CORS, cookie flags, certificate health, and a few safe read-only server probes — it does not attack or fuzz the site.
Everything on this page is a passive, read-only check of the audited URL. Audityxe is not a penetration-testing tool: it never sends exploit payloads, never tests for XSS or SQL injection, and never reads your source code.
What is checked
Security Headers
Header-level hardening read from the real response.
- HTTPS and HTTPS→HTTP redirect downgrade
- Strict-Transport-Security, including max-age, includeSubDomains, and HSTS preload-list eligibility
- Content-Security-Policy: script-src, style-src, object-src, base-uri, frame-ancestors, and enforcement vs. report-only mode
- X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy
- Cross-Origin-Opener-Policy, Cross-Origin-Embedder-Policy, Cross-Origin-Resource-Policy
- CORS configuration
- Server header exposure and X-Powered-By
- Cache-Control on a sensitive path
- Cookie security and cookie classification
- Mixed content and form-action security
SSL / TLS Certificate
A live TLS handshake and certificate-chain inspection.
- Certificate expiration
- Certificate issuer
- Hostname / SAN match
- TLS protocol version
- Cipher suite
- Key strength
Server Hardening
Safe, read-only probes.
- Dangerous HTTP methods
- Exposed configuration files
- Directory listing
Subresource Integrity & Link Safety
Third-party asset and link hygiene.
- Script SRI
- Stylesheet SRI
- Public JavaScript source-map exposure
- target="_blank" tabnabbing risk
Trust Signals
Vulnerability-disclosure readiness.
- security.txt vulnerability disclosure policy
How to run it
Web app: Paste the URL on the Audityxe homepage and open the Security category in the results.
Command line (see the CLI guide):
npx audityxe-cli https://example.com --min-score 80Frequently asked questions
Does Audityxe have a Content Security Policy (CSP) analyzer?
Yes. Audityxe evaluates the Content-Security-Policy header of the audited URL, including script-src, style-src, object-src, base-uri, frame-ancestors, and whether the policy is enforced or report-only.
Does Audityxe detect XSS vulnerabilities?
No. Audityxe does not test for cross-site scripting or any injection flaw. It only reads response headers, TLS, DNS, and a few exposed-file probes. A strong CSP reduces XSS impact, but Audityxe cannot tell you whether your application is vulnerable.
Is Audityxe a replacement for OWASP ZAP or a penetration test?
No. Audityxe is a passive configuration and hygiene audit. Use a dynamic scanner such as OWASP ZAP, or a professional penetration test, to look for exploitable vulnerabilities in applications you own.
Last reviewed against the Audityxe source code. Product names mentioned are trademarks of their respective owners; Audityxe is not affiliated with them.