API CodexAPI Codex
WebsiteDashboardGet API Key
  • Documentation
  • All APIs
  • Changelog
Resources
  • Docs Home
  • API Catalog
  • API Codex Website
Platform
  • Get a free API key
  • Dashboard
  • APIs & Pricing

© 2026 API Codex. All rights reserved.

Information
Other endpoints
    Scan a URL's HTTP security headersget
Schemas
powered by Zudoku
Security Headers Analyzer API

Security Headers Analyzer API

Scan any public web page and get an instant 0-100 security score, an A+ to F letter grade, the present/missing security-header map, and prioritized, severity-sorted remediation guidance.

The analyzer evaluates the eight headers that actually move the needle on web security: Strict-Transport-Security (HSTS), Content-Security-Policy (CSP, with heuristic checks for unsafe-inline, unsafe-eval, and wildcard sources), X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, Cross-Origin-Opener-Policy, and Cross-Origin-Resource-Policy. HSTS and CSP carry the heaviest weight because they matter most. It also flags information-leak headers such as Server and X-Powered-By.

100% edge-native: the only external data source is the fetch of the target URL itself. It follows redirects and reports final_url separately, bounds every request with a configurable timeout, and refuses to scan localhost and private addresses.

Get a free API key at dash.apicodex.io.

  • Instant scoring: Weighted 0-100 score and an A+ to F grade
  • Actionable: Severity-sorted recommendations from Critical to Info
  • Edge-native: Fast, consistent scans with no third-party scanners
API Codex Dashboard
Servers
https://api.apicodex.io/security-headers

API Codex