drheaderplus-mcp
MCP server for DrHeaderPlus — audit HTTP security headers from AI assistants.
Scans URLs or analyzes raw headers against security best practices: OWASP, CSP, HSTS, cookie flags, CORS misconfiguration, and more.
Available Tools
| Tool | Description |
|---|---|
scan_url |
Fetch headers from a URL and audit them. Detects missing headers, weak values, CSP issues, cookie misconfigurations, and CORS origin reflection. |
analyze_headers |
Audit a set of HTTP response headers directly (no network call). Use when you already have the headers. |
scan_bulk |
Scan multiple URLs and return per-URL results. Handles individual failures gracefully. |
list_presets |
List available ruleset presets (e.g. owasp-asvs-v14 for strict OWASP ASVS 4.0 V14 compliance). |
Tool Parameters
scan_url
url(required): The URL to scan (must include scheme, e.g.https://example.com)preset(optional): Ruleset preset namecross_origin_isolated(optional): Enable COEP/COOP checks (default: false)
analyze_headers
headers(required): HTTP response headers as key-value pairspreset(optional): Ruleset preset namecross_origin_isolated(optional): Enable COEP/COOP checks (default: false)
scan_bulk
urls(required): List of URLs to scanpreset(optional): Ruleset preset namecross_origin_isolated(optional): Enable COEP/COOP checks (default: false)
Installation
Using uvx (recommended, no install needed)
uvx drheaderplus-mcp
Using pip
pip install drheaderplus-mcp
Configuration
Claude Desktop
Add to your claude_desktop_config.json:
Using uvx:
{
"mcpServers": {
"drheaderplus": {
"command": "uvx",
"args": ["drheaderplus-mcp"]
}
}
}
Using pip installation:
{
"mcpServers": {
"drheaderplus": {
"command": "drheaderplus-mcp"
}
}
}
Claude Code
claude mcp add drheaderplus -- uvx drheaderplus-mcp
VS Code
Add to your .vscode/mcp.json:
{
"servers": {
"drheaderplus": {
"command": "uvx",
"args": ["drheaderplus-mcp"]
}
}
}
Debugging
Use the MCP inspector to test the server:
npx @modelcontextprotocol/inspector uvx drheaderplus-mcp
License
MIT
Metadata
Release files for drheaderplus-mcp 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| drheaderplus_mcp-0.1.0.tar.gz | 58.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| drheaderplus_mcp-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 63.4 kB
Release files / drheaderplus_mcp-0.1.0.tar.gz
| Download URL | drheaderplus_mcp-0.1.0.tar.gz |
|---|---|
| Size | 58.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
ff019720fd92f932041966ed92131723bd33b3f5c0317b74591ff8945d51ce4a
|
|
BLAKE2b-256 checksum How to use checksums |
0b239636eae4368e54555b50e264cce1f3c50789cca17060b5aadf883460b8eb
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.10.3 {"installer":{"name":"uv","version":"0.10.3","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / drheaderplus_mcp-0.1.0-py3-none-any.whl
| Download URL | drheaderplus_mcp-0.1.0-py3-none-any.whl |
|---|---|
| Size | 4.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
515853af3ec1326064b23c95704ddc0517bd6beb85cd2f461e80c45a2c7c470b
|
|
BLAKE2b-256 checksum How to use checksums |
2013115a576215cf108661b42af6a333c5fe995d2fe2271e10e7953f7801fdf4
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.10.3 {"installer":{"name":"uv","version":"0.10.3","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|