Skip to main content

vamp-ssl-audit

Python 3.9+ Platform License MIT VampSecure Labs CI

Overview

vamp-ssl-audit is a professional TLS/SSL configuration auditor with an SSLabs-inspired A+–F grading system. It tests protocol support (SSLv3 through TLS 1.3), cipher suite quality, certificate validity and key strength, and HTTP security headers. Each finding includes a concrete remediation recommendation. Reports export to JSON, HTML (dark-theme with grade badge), Markdown, and CSV — making it suitable for both interactive assessments and automated CI/CD pipelines.

Features

  • SSLabs-style letter grading from A+ (TLS 1.3 + complete HSTS + no legacy protocols) to F (null cipher, expired certificate, or connection failure)
  • Protocol detection: SSLv3 (CRITICAL, grade cap C), TLS 1.0/1.1 (CRITICAL/HIGH, cap B), TLS 1.2 (info), TLS 1.3 (info)
  • Cipher suite analysis: NULL/EXPORT/ADH/AECDH ciphers (CRITICAL, cap F); RC4/DES/MD5 (CRITICAL, cap C); 3DES (HIGH, cap B)
  • Certificate inspection: expiry and days remaining, key type and size (RSA < 1024 CRITICAL/F; RSA < 2048 HIGH/B; EC < 224 HIGH/B; DSA HIGH/B), signature algorithm (MD5 CRITICAL/C; SHA-1 HIGH/B), self-signed detection (HIGH/T), hostname coverage via SAN and CN
  • HTTP security header checks alongside TLS: HSTS (presence, max-age, includeSubDomains, preload), X-Frame-Options, X-Content-Type-Options
  • Multi-host concurrent scanning with configurable thread pool (--workers, default 5)
  • Custom port support (--port, default 443) and per-host HOST:PORT notation
  • Export to Console (Rich), JSON, HTML (dark-theme standalone with grade badge), Markdown, and CSV

Requirements

  • Python 3.9 or later
  • cryptography >= 41.0.0
  • rich >= 13.7.0

Installation

pip install vamp-ssl-audit
# o con Homebrew:
brew install vampsecure-labs/labs/vamp-ssl-audit
git clone https://github.com/belky-me/vamp-ssl-audit.git
cd vamp-ssl-audit
python3 -m venv .venv
source .venv/bin/activate   # Windows: .venv\Scripts\activate
pip install -r requirements.txt

Usage

python3 vamp_ssl_audit.py --help
usage: vamp_ssl_audit.py [-h] [-H HOST[:PORT]] [--file FILE]
                          [--port PORT] [--timeout TIMEOUT] [--workers WORKERS]
                          [--json FILE] [--html FILE]
                          [--markdown FILE] [--csv FILE]
                          [--client CLIENT] [--engagement ENGAGEMENT]
                          [--auditor AUDITOR] [--report-scope SCOPE]
                          [--report-html FILE] [--report-pdf FILE]

vamp-ssl-audit — TLS/SSL Professional Auditor (VampSecure Labs)

Try it now — public test targets

These hosts are publicly provided for testing TLS tools:

# Expired certificate → grade F
python3 vamp_ssl_audit.py -H expired.badssl.com

# Self-signed certificate → grade T
python3 vamp_ssl_audit.py -H self-signed.badssl.com

# TLS 1.0 still accepted → HIGH finding, grade cap B
python3 vamp_ssl_audit.py -H tls-v1.badssl.com

# SHA-1 signature → HIGH finding
python3 vamp_ssl_audit.py -H sha1-2016.badssl.com

# Clean A grade (standard well-configured host)
python3 vamp_ssl_audit.py -H badssl.com

Examples

# Audit a single host on default port 443
python3 vamp_ssl_audit.py -H example.com

# Audit with a non-standard port inline
python3 vamp_ssl_audit.py -H example.com:8443

# Audit multiple hosts in one command
python3 vamp_ssl_audit.py -H example.com -H api.example.com -H legacy.example.com

# Audit a list of hosts from file with 10 parallel workers
python3 vamp_ssl_audit.py --file hosts.txt --workers 10

# Export results to all formats
python3 vamp_ssl_audit.py -H example.com \
    --json results.json --html report.html --markdown report.md --csv report.csv

# With Let's Encrypt auto-renewal active, 90d alerts are noise — use 30d instead
python3 vamp_ssl_audit.py --file hosts.txt --warn-days 30

# Scan a non-HTTPS service on a custom default port
python3 vamp_ssl_audit.py --file smtp_hosts.txt --port 587

# Generate client-ready engagement report (HTML + PDF)
python3 vamp_ssl_audit.py --file hosts.txt \
    --client "Acme Corp" --engagement "TLS Configuration Review Q3 2026" \
    --auditor "J. Smith" --report-html client_report.html --report-pdf client_report.pdf

CI/CD Integration

Drop this into .github/workflows/ssl-audit.yml to gate your pipeline on TLS grade:

name: TLS Audit
on:
  schedule:
    - cron: '0 6 * * 1'   # weekly on Monday
  workflow_dispatch:

jobs:
  ssl-audit:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: actions/setup-python@v5
        with: { python-version: '3.12' }
      - run: pip install vamp-ssl-audit
      - run: |
          vamp-ssl-audit \
            -H yourdomain.com \
            -H api.yourdomain.com \
            --warn-days 30 \
            --json ssl-results.json \
            --markdown ssl-report.md
        # Exit code 1 = HIGH findings, 2 = CRITICAL findings → pipeline fails
      - uses: actions/upload-artifact@v4
        if: always()
        with:
          name: ssl-audit-report
          path: ssl-report.md

CLI Reference

Flag Default Description
-H / --host HOST[:PORT] — Target host, optionally with port (repeatable)
--file FILE — Text file with one host (or host:port) per line
--port N 443 Default port when not specified inline
--timeout N 10 Per-connection timeout in seconds
--workers N 5 Concurrent worker threads
--json FILE — Export results to JSON
--html FILE — Export dark-theme HTML report with grade badge
--markdown FILE — Export Markdown report
--csv FILE — Export CSV summary (+ FILE.findings detail file)
--warn-days N 90 Days ahead to issue MEDIUM cert-expiry alert. With Let's Encrypt auto-renewal, --warn-days 30 avoids noise (renewal runs at 30d, not 90d)
--client TEXT — Client name for VSL engagement report
--engagement TEXT — Engagement title for VSL engagement report
--auditor TEXT — Auditor name for VSL engagement report
--report-scope TEXT — Scope description for VSL engagement report
--report-html FILE — Export unified VSL client report (HTML)
--report-pdf FILE — Export unified VSL client report (PDF, requires fpdf2)

Output Formats

Format Flag Description
Console (default) Rich-colored graded output with finding tables and remediations
JSON --json FILE Machine-readable full result set
HTML --html FILE Dark-theme standalone report with letter-grade badge
Markdown --markdown FILE Portable report for audit repositories
CSV --csv FILE Summary row per host + FILE.findings with one row per finding
Client HTML --report-html FILE Unified VampSecure Labs engagement report
Client PDF --report-pdf FILE PDF version of the VSL client report

Grading Scale

Grade Criteria
A+ TLS 1.3 active, HSTS present and complete, no legacy protocols or weak ciphers
A Good configuration; HSTS absent or TLS 1.3 not offered
A- Good configuration; HSTS incomplete (short max-age, no includeSubDomains)
B TLS 1.0/1.1 present, 3DES, SHA-1 signature, or RSA < 2048
C SSLv3 accepted, RC4, or MD5 signature algorithm
D Very poor configuration
T Certificate not trusted: self-signed or hostname mismatch
F Critical failure: null cipher, expired certificate, or connection error

Exit Codes

Code Meaning CI/CD Behavior
0 No critical or high findings Pipeline passes
1 High-severity findings detected Pipeline fails — review required
2 Critical-severity findings detected Pipeline fails — immediate action required

Use exclusively on systems you own or for which you hold explicit written authorization from the system owner. VampSecure Studios assumes no liability for unauthorized use.

Part of VampSecure Labs Toolkit

vamp-ssl-audit is one tool in the VampSecure Labs security research toolkit. For the full toolkit including the orchestrator that runs all tools in sequence and aggregates findings into a single engagement report, see:


© VampSecure Studios — VampSecure Labs Security Research Division

Versión

v1.3.0 — VampSecure Labs Security Research Division

Metadata

Release files for vamp-ssl-audit 1.6.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for vamp-ssl-audit 1.6.0
File Size Uploaded
vamp_ssl_audit-1.6.0.tar.gz 65.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for vamp-ssl-audit 1.6.0
File Interpreter ABI Platform
vamp_ssl_audit-1.6.0-py3-none-any.whl Python 3 none any Details

Total release size: 123.8 kB

Release files / vamp_ssl_audit-1.6.0.tar.gz

Download URL vamp_ssl_audit-1.6.0.tar.gz
Size 65.2 kB
Tags Source
SHA-256 checksum
How to use checksums
a10cddf3afc011ac67028d9ae6683d364a8bc406cece070ea7a595a42b79497e
BLAKE2b-256 checksum
How to use checksums
244611f3477afc1a0075874c407b6159ddc155ced65bc7a4ce70b15d8661ab98
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.9.6

Release files / vamp_ssl_audit-1.6.0-py3-none-any.whl

Download URL vamp_ssl_audit-1.6.0-py3-none-any.whl
Size 58.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
234a3980531cec689a5fc949ede6c534593b27fccd922326441ae27f9a8a9879
BLAKE2b-256 checksum
How to use checksums
0f633122287b1b3e0b7fdf4c6003dae0dad3dbdce9242117f777d588e208b819
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.9.6

Release history Release notifications | RSS feed

1.7.0

2 release files

This release

1.6.0 This release

2 release files

1.5.0

2 release files

1.4.0

2 release files

1.3.0

2 release files

1.2.0

2 release files

1.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page