We reply immediately
The OWASP Secure Headers Project
Stats about HTTP response security headers usage mentioned by the OSHP.
An application to catch, search and analyze HTTP secure headers.
An easy way to up and running a web interface to navigate in data collected by headers core script.
🐍 Manage and run your integration tests with efficiency - Venom run executors (script, HTTP Request, web, imap, etc... ) and assertions
Venom tests suite to validate an HTTP security response headers configuration against OSHP recommendation.
Repository used to organize freely the work on the OSHP projects.
Event Driven WebSockets Framework with Cross-Browser Fallbacks
Apache module for rewriting web pages to reduce latency and bandwidth.
Automatic PageSpeed optimization module for Nginx
Nmap - the Network Mapper. Github mirror of official SVN repository.
Manages application of security headers with many safe defaults
WebAppSec Clear Site Data
A collection of browser-based side channel attack vectors.
A mechanism to selectively enable and disable browser features and APIs
A security scanner for HTTP response headers.
A humble, and 𝗳𝗮𝘀𝘁, security-oriented HTTP headers analyzer.
Mozilla HTTP Observatory
Mozilla Observatory (Website)
Testing TLS/SSL encryption anywhere on any port
drHEADer helps with the audit of security headers received in response to a single request or a list of requests.
Small package to allow adding security headers to ASP.NET Core websites
Manages application of security headers with many safe defaults
A PHP library aiming to make the use of browser security features more accessible.
PHP Secure Headers
Security related headers for Rack applications
Help secure Express apps with various HTTP headers
a hapi CSP plugin
Content Security Policy for Django.
A collection of models, views, middlewares, and forms to help secure a Django project.
Lightweight modern Python library to add security headers (CSP, HSTS, etc.) to Django, Flask, FastAPI, and more. Secure defaults or fully customizable.
HTTP security middleware for Go(lang) inspired by HelmetJS.
A mechanism to selectively enable and disable browser features and APIs