{"uid":"cap_jaJFzXiqQ6btSkWzVW5zb","slug":"hubvibe-security-headers-audit-325bd62c","name":"HubVibe Security Headers Audit","description":"Security headers check for a website: audits HTTPS, HSTS, Content- Security-Policy (CSP), X-Content-Type-Options, X-Frame-Options / clickjacking protection, Referrer-Policy and CORS from the real HTTP response of any live URL. Findings with severity for what is missing. Header posture only, not a penetration test.","url":"https://hubvibe-io.com/audit/security","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"url":{"type":"string","format":"uri","examples":["https://example.com"],"description":"Live, fetchable http(s) URL to audit."}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.05","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.05/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_ck-ETYOfe-UNhhzYqTB2S","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.05","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Audits a live URL for HTTP security headers including HTTPS, HSTS, CSP, X-Content-Type-Options, clickjacking protection, Referrer-Policy, and CORS","exampleAgentPrompt":"Can you run a security headers audit on https://mystore.example.com and tell me if HTTPS, HSTS, CSP, clickjacking protection, Referrer-Policy, and CORS are all properly configured?","exampleUseCases":[{"title":"Pre-launch security header check","prompt":"Before we go live with our new site at https://staging.acmecorp.com, can you audit its security headers and tell me if HTTPS, HSTS, CSP, clickjacking protection, Referrer-Policy, and CORS are all set correctly?"},{"title":"Compliance verification for client site","prompt":"I need to verify that https://client-portal.example.com has all the standard HTTP security headers in place — HSTS, Content Security Policy, X-Content-Type-Options, anti-clickjacking, Referrer-Policy, and CORS. Can you run that check now?"},{"title":"Monitoring security regression after deploy","prompt":"We just deployed a new build to https://app.mybusiness.io — can you audit the security headers to make sure HTTPS enforcement, HSTS, CSP, and CORS are still configured correctly and nothing regressed?"}],"resultDescription":"Returns a structured audit report of HTTP security headers from a live response to the given URL, indicating the presence, absence, or misconfiguration of HTTPS enforcement, HSTS, Content Security Policy, X-Content-Type-Options, clickjacking protection (X-Frame-Options or CSP frame-ancestors), Referrer-Policy, and CORS headers.","failureModes":["URL is unreachable or returns a non-200 response — audit cannot be completed","Target site blocks automated requests or requires authentication","CORS or firewall rules block the auditing service from fetching headers","Malformed or missing URL input returns a validation error","Timeout if the target server responds too slowly"],"whenToPreferThis":"Choose this endpoint when you need a fast, live check of HTTP security response headers for a specific URL without running a full penetration test or TLS cipher analysis. It is ideal for pre-launch checks, post-deploy regression monitoring, or compliance verification where the goal is confirming standard browser-enforced security headers (HSTS, CSP, CORS, etc.) are present and correctly configured. Prefer this over full-stack security scanners when you only need header-level validation quickly and cheaply.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T12:48:17.769Z","isFirstParty":false}