Open source · Security & Privacy

HTTP Security Header Auditor

Check security headers against a declared policy and route exceptions.

v0.1.0 · Node.js 22+ · MIT

Browse the public repository · View releases

Evaluate captured HTTP response header fields against a declared policy and its route exceptions, and explain what is missing and what contradicts itself — entirely offline.

This walkthrough uses the tool's public README and checked-in example files. Run the command from a repository checkout with Node.js 22+; inspect the source before using it on your own files.

Run the checked-in example

$ npx http-security-header-auditor --root ./headers --as-of 2026-03-01
$ npx http-security-header-auditor --root ./headers --as-of 2026-03-01 --json | jq '.summary'
$ npx http-security-header-auditor --help

Read the result

--root holds two files: policy.json and capture.json. Rename either with --policy and --capture; both stay relative to the root, and a path that resolves outside it — through a symbolic link included — is refused unread.

Where this check stops

Why a route has no URL. The capture schema has no url, host, origin or endpoint key, and an unknown key is refused rather than ignored. That is the structural half of "nothing is ever fetched": a tool whose input has no address in it cannot resolve one by accident, and a future change that wanted to would have to add the field first, in public, in a schema version bump.

Before adapting the command to your own workflow, review the accepted inputs, exit codes and safety boundaries in the README.

Compiled with AI assistance from checked-in public documentation and example scripts. Run the example and review the repository's current documentation before relying on its result.