Scan one or hundreds of websites for common security misconfigurations — HTTP security headers, SSL/TLS certificates, HSTS and cookie flags — from a single terminal command.
Born from a real pain point: validating security policies across a list of dozens of internal URLs after a deploy. What took almost an hour of manual clicking (DevTools → headers → SSL tester → HSTS preload site) now takes seconds.
📖 Read the story behind this tool: Como Automatizei uma Verificação de Segurança Web com um Script Python
| Category | Checks |
|---|---|
| Transport | HTTP → HTTPS redirect · TLS certificate hostname match · certificate validity ≤ 398 days |
| HSTS | Strict-Transport-Security header · includeSubDomains · presence on the HSTS preload list (via official API) |
| CSP | Content-Security-Policy presence · flags unsafe-eval and unsafe-inline |
| Cookies | Secure and HttpOnly attributes on all cookies |
| Info disclosure | Server header exposure |
| Headers | X-Content-Type-Options: nosniff · X-Frame-Options: DENY/SAMEORIGIN |
Results are printed as a color-coded [PASS] / [FAIL] / [WARN] / [INFO] report per URL.
Requires Python 3.8+.
git clone https://github.com/Silva-Sec/WebSecurityPolicyScanner.git
cd WebSecurityPolicyScanner
pip install -r requirements.txtScan a single domain:
python wsps.py github.comScan a list of URLs (one per line):
python wsps.py urls_to_validate.txtExample input file:
github.com
https://example.org/login
internal-app.corp.local
==================================================
Analyzing: github.com
==================================================
[INFO] Checking HTTP -> HTTPS redirect...
[PASS] HTTP correctly redirects to HTTPS.
[INFO] Checking SSL certificate...
[PASS] Hostname 'github.com' matches the SSL certificate.
[PASS] SSL validity period is 365 days (within the 398-day limit).
[INFO] Checking HSTS Preload List...
[PASS] Domain status is 'preloaded' on the HSTS Preload List.
[INFO] Analyzing security headers...
[PASS] CSP is implemented.
[PASS] CSP does not contain 'unsafe-eval'.
...
- Security score (A–F grade per URL)
- TLS version detection (flag TLS 1.0/1.1)
- SameSite cookie attribute check
- Modern headers: COOP, CORP, COEP, Referrer-Policy, Permissions-Policy
- CSV/JSON report export for batch audits
Contributions are welcome — open an Issue or a Pull Request.
Jonathan Silva — Security Researcher & Infrastructure Specialist.
- 🌐 silvasec.com
- ✍️ silvasec.seg.br
- 🐦 @SilvaSec
MIT © 2026 Jonathan Silva