About
In April 2026, SecurityHeaders.com shut down its API — the free tool that thousands of pentesters and developers used to programmatically check HTTP security headers. The replacement options were either expensive SaaS platforms or half-broken open source projects.
WebAudit fills that gap, and goes further. HTTP headers are only one layer of a site's security posture, so a single scan covers TLS certificate analysis (protocol, cipher strength, expiry, and issuer), DNS and email security (SPF, DMARC, DKIM, CAA, and DNSSEC), cookie flag auditing (Secure, HttpOnly, SameSite), and cross-origin isolation checks that most header-only tools skip entirely.
The result is a complete replacement rather than a partial one: every scan runs instantly with no login, and Pro users can export the findings as a client-ready PDF report you can hand to a CTO without embarrassment.
Privacy. Scans run against live HTTP requests to the URL you enter, and the results aren't stored, resold, or used to build a profile. No account, no credit card, and no email are required to run a scan.
Transparency. The A–F grade is deterministic — every point deduction maps to a documented rule, not a black box or a human opinion. The full scoring methodology is public, so you can reproduce and explain any grade WebAudit gives.
Standards-based. The checks map to recognised security standards and best practices — OWASP guidance, established HTTP security-header recommendations, and TLS and DNS hygiene — rather than arbitrary preferences.
Built for real use. Every finding comes with the exact, copy-paste fix needed to resolve it, and the same findings export into a clean, client-ready report. It's a tool built to be used in real audits, not just to produce a number.
Found a bug? Want a feature? Have a scan that returned wrong results? Email hello@webaudit.in — I read every message.
For API access and PDF exports, see the Plans page — checkout is automatic and routes to the right payment option for your location.