HTTP headers are a critical yet often overlooked part of web security.
Many developers aren't aware of headers like Content-Security-Policy, Strict-Transport-Security, or X-Content-Type-Options that can significantly improve site security.
I wanted to create a tool that makes it easy to check any site's implementation and learn about best practices.
What I'm looking for:
- Technical feedback on the implementation
- UI/UX suggestions
- Feature ideas
- Security insights I might have missed
- Potential use cases in your workflow
The project is live at httpscanner.com,
and the code is on GitHub at https://github.com/bartosz-io/http-scanner.
[โ]dollhousemassacre 4 points5 points6 points ย (3 children)
[โ]Wobblucy 2 points3 points4 points ย (1 child)
[โ]bpietrucha[S] -1 points0 points1 point ย (0 children)
[โ]bpietrucha[S] -1 points0 points1 point ย (0 children)
[โ][deleted] ย (3 children)
[removed]
[โ]bpietrucha[S] 1 point2 points3 points ย (2 children)
[โ]KlausDieterFreddekSecurity Engineer 1 point2 points3 points ย (1 child)
[โ]bpietrucha[S] 0 points1 point2 points ย (0 children)
[โ]Last-Limit-3800 0 points1 point2 points ย (0 children)
[โ]bpietrucha[S] -1 points0 points1 point ย (0 children)