Skip to main content

vamp-http-audit

Python 3.9+ Platform License MIT VampSecure Labs CI

Overview

vamp-http-audit is the HTTP layer companion to vamp-ssl-audit. Where the TLS auditor covers the transport layer, this tool covers HTTP security headers, CORS misconfigurations, cookie flag analysis, server information disclosure, and open redirect vulnerabilities. It uses the same SSLabs-style A+–F grading system and supports the same output formats (JSON, HTML, Markdown, CSV), making it a natural fit in any automated assessment pipeline.

Features

  • SSLabs-style letter grading A+ to F based on combined HTTP security posture
  • Security header analysis: CSP (directive-level deep inspection including unsafe-inline, unsafe-eval, wildcards, frame-ancestors), HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, COEP, COOP, CORP
  • CORS misconfiguration probing: attacker-origin reflection, wildcard + credentials (CRITICAL), null-origin acceptance (iframe sandbox bypass)
  • Cookie security analysis: Secure, HttpOnly, SameSite flags; __Host- and __Secure- prefix enforcement
  • Server information disclosure detection: Server, X-Powered-By, X-AspNet-Version, X-AspNetMvc-Version, X-Generator, debug headers
  • Open redirect testing across 16 common parameters: url, redirect, next, return, goto, destination, redir, target, link, forward, location, rurl, returl, redirect_uri, redirect_url, return_url
  • GraphQL endpoint detection and introspection availability check
  • Concurrent multi-URL scanning with configurable worker pool (--workers, default 5)
  • Zero third-party dependencies — only Python stdlib (urllib) and rich
  • Export to Console, JSON, HTML (dark-theme with collapsible remediations), Markdown, and CSV

Requirements

  • Python 3.9 or later
  • rich >= 13.7.0

Installation

pip install vamp-http-audit
# o con Homebrew:
brew install vampsecure-labs/labs/vamp-http-audit
git clone https://github.com/belky-me/vamp-http-audit.git
cd vamp-http-audit
python3 -m venv .venv
source .venv/bin/activate   # Windows: .venv\Scripts\activate
pip install -r requirements.txt

Usage

python3 vamp_http_audit.py --help
usage: vamp_http_audit.py [-h] [-u URL] [--file FILE]
                           [--timeout TIMEOUT] [--workers WORKERS]
                           [--json FILE] [--html FILE]
                           [--markdown FILE] [--csv FILE]
                           [--no-verify-ssl]
                           [--client CLIENT] [--engagement ENGAGEMENT]
                           [--auditor AUDITOR] [--report-scope SCOPE]
                           [--report-html FILE] [--report-pdf FILE]

vamp-http-audit — HTTP Security Headers & CORS Auditor (VampSecure Labs)

Try it now — public test targets

No targets of your own? These intentionally-misconfigured hosts are safe to scan:

# No HSTS → grade drops to C
python3 vamp_http_audit.py -u https://nohsts.badssl.com

# X-Frame-Options absent → clickjacking surface
python3 vamp_http_audit.py -u https://no-x-frame-options.badssl.com

# Typical modern site for comparison
python3 vamp_http_audit.py -u https://badssl.com

Quick wins — going from B to A in nginx

These three directives cover the most common gap (CSP absent → HIGH):

# nginx.conf or site vhost
server_tokens off;   # hides nginx version from Server header

add_header Content-Security-Policy
  "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline';
   img-src 'self' data: https:; frame-ancestors 'none';"
  always;

add_header Permissions-Policy
  "geolocation=(), camera=(), microphone=()"
  always;

For SPAs (React, Vue, Next.js, Svelte) the script-src 'self' will break inline scripts. Use a nonce-based CSP or add 'unsafe-inline' temporarily while hardening:

# Next.js: also suppress framework fingerprinting
proxy_hide_header X-Powered-By;

COEP / COOP / CORP — vamp-http-audit flags these as LOW. They are only critical for sites using SharedArrayBuffer or cross-origin isolation. For most sites (blogs, dashboards, SaaS UIs without WebWorkers) these findings can be safely ignored.

CI/CD Integration

name: HTTP Security Audit
on:
  schedule:
    - cron: '0 7 * * 1'
  workflow_dispatch:

jobs:
  http-audit:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: actions/setup-python@v5
        with: { python-version: '3.12' }
      - run: pip install vamp-http-audit
      - run: |
          vamp-http-audit \
            -u https://yourdomain.com \
            -u https://api.yourdomain.com \
            --json http-results.json \
            --markdown http-report.md
        # Exit 1 = HIGH findings, exit 2 = CRITICAL (open redirect, CORS+creds)
      - uses: actions/upload-artifact@v4
        if: always()
        with:
          name: http-audit-report
          path: http-report.md

Examples

# Audit a single URL
python3 vamp_http_audit.py -u https://example.com

# Audit multiple URLs in one command
python3 vamp_http_audit.py -u https://example.com -u https://api.example.com

# Audit a list of URLs from file with 10 parallel workers
python3 vamp_http_audit.py --file urls.txt --workers 10

# Export results to all formats
python3 vamp_http_audit.py -u https://example.com \
    --json results.json --html report.html --markdown report.md --csv report.csv

# Skip TLS verification for self-signed certificates
python3 vamp_http_audit.py -u https://internal.staging.local --no-verify-ssl

# Generate client-ready engagement report
python3 vamp_http_audit.py --file urls.txt \
    --client "Acme Corp" --engagement "HTTP Headers Review Q3 2026" \
    --auditor "J. Smith" --report-html client_report.html

CLI Reference

Flag Default Description
-u / --url URL — Target URL (repeatable for multiple targets)
--file FILE — Text file with one URL per line
--timeout N 10 Per-request timeout in seconds
--workers N 5 Concurrent worker threads
--json FILE — Export results to JSON
--html FILE — Export dark-theme HTML report
--markdown FILE — Export Markdown report
--csv FILE — Export CSV summary (+ FILE.findings detail file)
--no-verify-ssl off Disable TLS certificate verification
--client TEXT — Client name for VSL engagement report
--engagement TEXT — Engagement title for VSL engagement report
--auditor TEXT — Auditor name for VSL engagement report
--report-scope TEXT — Scope description for VSL engagement report
--report-html FILE — Export unified VSL client report (HTML)
--report-pdf FILE — Export unified VSL client report (PDF, requires fpdf2)

Output Formats

Format Flag Description
Console (default) Rich-colored graded output with per-finding remediation panels
JSON --json FILE Machine-readable full result set
HTML --html FILE Dark-theme standalone report with collapsible remediations
Markdown --markdown FILE Portable report for inclusion in audit repositories
CSV --csv FILE Summary row per host + FILE.findings with one row per finding
Client HTML --report-html FILE Unified VampSecure Labs engagement report
Client PDF --report-pdf FILE PDF version of the VSL client report

Grading Scale

Grade Criteria
A+ All headers present, solid CSP, secure cookies, no CORS issues
A Good configuration; missing COOP/COEP/CORP or SameSite on some cookies
A- CSP with unsafe-inline/eval/wildcard; suboptimal Referrer-Policy
B CSP absent · X-Content-Type-Options absent · server version exposed · insecure cookie · CORS wildcard without credentials
C X-Frame-Options absent without frame-ancestors · HSTS absent
F CORS wildcard + credentials · confirmed open redirect

Exit Codes

Code Meaning CI/CD Behavior
0 No critical or high findings Pipeline passes
1 High-severity findings detected Pipeline fails — review required
2 Critical-severity findings detected Pipeline fails — immediate action required

Use exclusively on systems you own or for which you hold explicit written authorization from the system owner. VampSecure Studios assumes no liability for unauthorized use.

Part of VampSecure Labs Toolkit

vamp-http-audit is one tool in the VampSecure Labs security research toolkit. For the full toolkit including the orchestrator that runs all tools in sequence and aggregates findings into a single engagement report, see:


© VampSecure Studios — VampSecure Labs Security Research Division

Versión

v1.2.0 — VampSecure Labs Security Research Division

Metadata

Release files for vamp-http-audit 1.3.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for vamp-http-audit 1.3.0
File Size Uploaded
vamp_http_audit-1.3.0.tar.gz 59.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for vamp-http-audit 1.3.0
File Interpreter ABI Platform
vamp_http_audit-1.3.0-py3-none-any.whl Python 3 none any Details

Total release size: 114.5 kB

Release files / vamp_http_audit-1.3.0.tar.gz

Download URL vamp_http_audit-1.3.0.tar.gz
Size 59.1 kB
Tags Source
SHA-256 checksum
How to use checksums
0c438bb4eea5ad23238ced133cc792811405f972fddbc40dc547fbf7e9746b2b
BLAKE2b-256 checksum
How to use checksums
167f56bce711d9e0adbbbfba489508119278690dc51a589f9b4f11b6bb1251b3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.9.6

Release files / vamp_http_audit-1.3.0-py3-none-any.whl

Download URL vamp_http_audit-1.3.0-py3-none-any.whl
Size 55.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
5b8c90aed9c0e21152e21ba958c46a8d6d0746a523d60ad1b523a684c2be94c4
BLAKE2b-256 checksum
How to use checksums
4cc605c1454a49a6376303566595c1be937a64573ac97ef8594fc84355aab831
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.9.6

Release history Release notifications | RSS feed

This release

1.3.0 This release

2 release files

1.2.0

2 release files

1.1.0

1 release file

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page