ToolAssay

Compare a fixed list of ten security-relevant response headers across two releas

Compare a fixed list of ten security-relevant response headers across two releases and name the specific reverts. Reports a header removed, added or changed, and separately a reduced Strict-Transport-Security max-age, dropped includeSubDomains, a newly permitted unsafe-inline or unsafe-eval, and a Content-Security-Policy that moved from enforcing to report-only so it no longer blocks anything. Observable differences only, not an assessment of whether either configuration is adequate.

Answeringour last check, 2026-10-04
1 of 1checks answered this week
2487 msmedian answer time
$0.11listed price per call
$0.11price it asked us

Paid test badge: not yet. The checks above are free: we call the tool without paying and read the payment request it sends back. The Verified badge needs paid calls whose answers match the promised output, and nobody can buy a badge.

Endpoint

POST https://api.zfinia.com/x402/v1/security-header-diff

CategoryEverything else
Provider hostapi.zfinia.com
Networkseip155:8453
Payment schemesexact
Self-reported calls, 30 days1 from 1 payers (the provider's figure, not ours)

Our checks, last 30 days

DayResultHTTPAskedTime
2026-10-04 valid payment request 402$0.11 2487 ms

Example input (from the provider)

{
  "body": {
    "after": {
      "Content-Security-Policy-Report-Only": "default-src 'self'; script-src 'self' 'unsafe-inline'",
      "Referrer-Policy": "no-referrer",
      "Strict-Transport-Security": "max-age=600",
      "X-Frame-Options": "SAMEORIGIN"
    },
    "after_name": "release-42",
    "before": {
      "Content-Security-Policy": "default-src 'self'; script-src 'self'",
      "Referrer-Policy": "no-referrer",
      "Strict-Transport-Security": "max-age=31536000; includeSubDomains",
      "X-Content-Type-Options": "nosniff",
      "X-Frame-Options": "DENY"
    },
    "before_name": "release-41"
  },
  "bodyType": "json",
  "method": "POST",
  "type": "http"
}

Promised output schema (from the provider)

{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "properties": {
    "input": {
      "additionalProperties": false,
      "properties": {
        "body": {
          "additionalProperties": false,
          "properties": {
            "after": {
              "type": "object"
            },
            "after_name": {
              "maxLength": 64,
              "type": "string"
            },
            "before": {
              "type": "object"
            },
            "before_name": {
              "maxLength": 64,
              "type": "string"
            }
          },
          "required": [
            "before",
            "after"
          ],
          "type": "object"
        },
        "bodyType": {
          "enum": [
            "json",
            "form-data",
            "text"
          ],
          "type": "string"
        },
        "method": {
          "enum": [
            "POST"
          ],
          "type": "string"
        },
        "type": {
          "const": "http",
          "type": "string"
        }
      },
      "required": [
        "type",
        "method",
        "bodyType",
        "body"
      ],
      "type": "object"
    },
    "output": {
      "properties": {
        "example": {
          "type": "object"
        },
        "type": {
          "type": "string"
        }
      },
      "required": [
        "type"
      ],
      "type": "object"
    }
  },
  "required": [
    "input"
  ],
  "type": "object"
}

This page as JSON