TLS/Transport
Protocol version, cipher strength/forward secrecy, certificate chain/expiry/hostname, OCSP stapling, HTTPS redirect, and HSTS.
Ce contenu n’est pas encore disponible dans votre langue.
TLS/Transport
Protocol version, cipher strength/forward secrecy, certificate chain/expiry/hostname, OCSP stapling, HTTPS redirect, and HSTS.
HTTP Security Headers
CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, banner disclosure, and cookie flags.
Header Trust Boundary
X-Forwarded-For, X-Real-IP, True-Client-IP, X-Forwarded-Host, and RFC 7239 Forwarded consistency.
Information Disclosure
Verbose error pages, exposed proxy admin/status interfaces, directory listing, and config/secrets file exposure.
proxyaudit scan https://proxy.example.comEvery check is non-destructive and read-only (single or few requests, no brute-forcing or state mutation). Exit codes are CI-friendly: 0 no findings, 1 findings present, 2 runtime/connection error.