⚙️ NGINX config generator on steroids 💉
-
Updated
Dec 14, 2024 - JavaScript
⚙️ NGINX config generator on steroids 💉
Comprehensive Content Security Policy (CSP) Guide & Suite in Arabic. Learn web security, prevent XSS, and implement robust security headers.
A powerful Chrome Extension (Manifest V3) for passive web reconnaissance, OSINT gathering, security headers analysis, passive vulnerability indicators (PVI), and PDF report generation.
Chrome MV3 extension that inspects any URL: metadata, DNS, RDAP, IP geo, security headers, Mozilla Observatory grade, Lighthouse scores, and more — all from free, no-key public APIs.
Read-only MCP server for fyzno.com. Three free reports on any domain: mail security, website security, and DNS hygiene. Zero dependencies.
Certify your citadel. Passive, authorized external security-posture assessment that grades TLS, HTTP headers, cookies, DNS and email auth across a company's assets and issues a leveled certificate + badge. Zero dependencies. Never exploits, only inspects what you authorize.
Instant web security analysis: detect vulnerabilities in HTTP headers, TLS, and CORS with a single scan
Chrome extension that scans web apps for security vulnerabilities using CISA KEV catalog and NVD verification
Chrome extension (Manifest V3) that grades the security of the page you're on, A to F: TLS certificate, security headers, cookies, API calls, hardcoded secrets and vulnerable JS libraries. 100% local, no telemetry, zero dependencies.
MCP server for Website Security Snapshot API — scan security headers from Claude via x402
CLI security and attack-surface audit tool for websites. Runs unauthenticated checks (security headers, TLS, CMS/CDN fingerprinting, exposed admin paths, CVEs, subdomains, open ports, PII leaks, CORS) and outputs a risk-graded HTML/PDF dashboard, CSV data, and a ticket-ready backlog.
Audit HTTP security-header docs for CSP, HSTS, clickjacking, nosniff, referrer policy, permissions policy, CORS, cookies, cache/download headers, reporting, rollout, and tests.
everthread on npm: a plain-English website security check for the terminal, plus an MCP server for agents
Security headers for static hosts — CSP, HSTS, cross-origin isolation. Writes a _headers file; Astro integration included.
GitHub Action: check any website for EU compliance basics — privacy, terms, cookie consent, imprint, accessibility statement, DPA. Zero deps
Express middleware with rate limiting, fingerprinting, Cloudflare-aware IP trust, and essential security headers.
One command that audits a page for accessibility, Core Web Vitals, technical SEO and header security, and reports the WCAG criteria no scanner can check. HTML, Markdown and JSON reports, budgets and CI exit codes.
Universal website compliance scanner — GDPR, DSA, ePrivacy, security headers, cookie consent. Platform-independent: works on any URL, any CMS.
MCP server: free web tools for AI agents — HTML→Markdown, EU compliance scan, page profile, security headers. Zero auth, zero dependencies.
Prioritizes passive web security findings and connects them to evidence, remediation, and retesting.
To associate your repository with the security-headers topic, visit your repo's landing page and select "manage topics."