AuthorRicardo Iramar
OSHP is short for OWASP SecureHeaders Project. The project publishes reports on the usage of HTTP headers. This includes usage stats, developments, and changes. It provides awareness on HTTP headers and has the goal to improve the adoption rate.

OSHP is commonly used for data extraction, information gathering, information sharing, or security awareness. Target users for this tool are security professionals.

  • + The source code of this software is available

OSHP is under development by Ricardo Iramar. This project is currently maintained by Alexandre Menezes, Jim Manico.


OSHP is known to work on Linux.


  • appdirs
  • blinker
  • click
  • contextlib2
  • Flask
  • Flask-Caching
  • Flask-Compress
  • gevent
  • greenlet
  • gunicorn
  • itsdangerous
  • jinja2
  • MarkupSafe
  • mysql-connector
  • newrelic
  • packaging
  • raven
  • Redis
  • six
  • Werkzeug

Django-security is a toolkit for the Django framework with the focus on security. It provides models, views, and middleware to strengthen the defenses.



hsecscan performs a security scan of a website and analyses any discovered HTTP headers. For each header, it will provide details and recommendations.



Security header check (shcheck) is a security tool to scan web applications and their HTTP headers. It can help securing web applications or detect weaknesses.

