RS

rfc-st/humble

开发工具
372 stars 质量 41 趋势 41

humble A humble, and fast, security-oriented HTTP headers analyzer

概览

humble A humble, and fast, security-oriented HTTP headers analyzer

README

humble A humble, and fast, security-oriented HTTP headers analyzer

“千里之行,始於足下 - 老子”

(“A journey of a thousand miles begins with a single step. - Lao Tzu”)

“And if you don’t keep your feet, there’s no knowing where you might be swept off to. - Bilbo Baggins”

Table of contents

Features Screenshots Installation & Update (Source code) Installation & Maintenance (Docker) Installation & Update (Kali Linux) Usage Advanced Usage (Linux) Unit tests Quality, style and security tools Checks: Missing Headers Checks: Fingerprint Headers Checks: Deprecated Headers and Insecure Values Checks: Empty Values Global skip file Guidelines included To-Do Further Reading Contribute Acknowledgements License

Features

:heavy_check_mark: Covers 63 enabled security-related HTTP response headers. :heavy_check_mark: 15 checks for missing security-related HTTP response headers (the ones I consider essential). :heavy_check_mark: 1288 checks for fingerprinting through HTTP response headers. :heavy_check_mark: 159 checks for deprecated HTTP response headers/protocols or with insecure/wrong values. :heavy_check_mark: 28 checks related to Content Security Policy Level 3. :heavy_check_mark: Can check for compliance with the OWASP Secure Headers Project Best Practices. :heavy_check_mark: Can exclude specific HTTP response headers from the analysis. :heavy_check_mark: Can analyze raw response and HAR files. :heavy_check_mark: Can export analysis to CSV, CSS3/HTML5, JSON, PDF, TXT, XLSX, XML and with a custom filename/path. :heavy_check_mark: Can check for outdated SSL/TLS protocols and vulnerabilities: requires the amazing testssl.sh. :heavy_check_mark: Can provide brief and detailed analysis along with HTTP response headers. :heavy_check_mark: Can use proxies for the analysis. :heavy_check_mark: Allows specifying custom HTTP request headers. :heavy_check_mark: Can output only analysis summary, totals and grade as JSON; suitable for CI/CD. :heavy_check_mark: Print browser support for enabled HTTP security headers, with data from Can I use. :heavy_check_mark: Highlights experimental headers in each analysis. :heavy_check_mark: Provides hundreds of relevant links to security resources, standards and technical blogs based on each analysis. :heavy_check_mark: Supports displaying analysis, messages, and most errors in English or Spanish. :heavy_check_mark: Saves each analysis, highlighting improvements or deficiencies compared to the previous one. :heavy_check_mark: Can display analysis statistics for a specific URL or across all of them. :heavy_check_mark: Can display fingerprint statistics for a specific term or the Top 20. :heavy_check_mark: Can display guidelines for enabling security HTTP response headers on popular frameworks, servers, and services. :heavy_check_mark: Can exclude HTTP response headers across all analyses via humble.skip file. :heavy_check_mark: AI-driven security triage and remediation guidance. :heavy_check_mark: Includes over 100 unit tests to help verify it works correctly in your environment; requires pytest and pytest-cov. :heavy_check_mark: Classes and functions documented at Read the Docs. :heavy_check_mark: Code regularly audited with several quality, style and security tools. :heavy_check_mark: Tested, one by one, on thousands of URLs. :heavy_check_mark: Tested on Docker 26.1, Kali Linux 2021.1, macOS 14.2.1 and Windows 10 20H2. :heavy_check_mark: Almost all the code available under one of the most permissive licenses: MIT. :heavy_check_mark: Regularly updated. :heavy_check_mark: Minimal dependencies required. :heavy_check_mark: Developed in my spare time over the last six years; feel free to integrate it into your projects. No strings attached!. :heavy_check_mark: And with the approval of several AI :smile:!.

Screenshots

.: (Windows) - Brief analysis.

.: (Linux) - Brief analysis along with HTTP response headers.

.: (Linux) - Detailed analysis, in Spanish.

.: (Linux) - Analysis of a raw response file. Example.

[!TIP] Generating a raw response file; requires curl 8.16 or higher:

curl --dump-header github_input_file.txt https://github.com --out-null -s

.: (Linux) - SSL/TLS checks.

[!TIP] testssl.sh options used:

  • -f: checks robust forward secrecy key exchange
  • -g: checks several server implementation bugs
  • -p: checks the availability of SSL/TLS protocols
  • -U: tests all vulnerabilities, like Heartbleed, ROBOT and sweet32
  • -s: tests lists of cipher suites/categories by strength
  • -hints: (available in the future) give hints how to fix a finding

.: (Linux) - Custom HTTP request header.

.: (Linux) - Compliance with OWASP ‘Secure Headers Project’ best practices.

.: (Linux) - JSON summary of the analysis, suitable for CI/CD.

.: (Linux) - List of HTTP fingerprint headers based on a specific term.

.: (Windows) - Guidelines for enabling security HTTP response headers.

.: (Linux) - Brief analysis saved as CSV. Example.

.: (Windows) - Detailed analysis saved as PDF. Example.

.: (Linux) - Detailed analysis saved as HTML. Example.

.: (Linux) - Detailed analysis saved as JSON. Example.

.: (Linux) - Detailed analysis saved as XLSX. Example.

.: (Linux) - Brief analysis saved as XML. Example.

.: (Linux) - Analysis history file: Date, URL, Enabled, Missing, Fingerprint, Deprecated/Insecure, Empty headers & Total warnings (the four previous totals).

.: (Linux) - Statistics of the analysis performed against a specific URL.

.: (Linux) - Statistics of the analysis performed against all URLs, in Spanish.

.: (Windows) - Checking for updates

Installation & update (Source code)

[!NOTE] Python 3.11 or higher is required.

# Install python3 and python3-pip:
# (Windows) https://www.python.org/downloads/windows/
# (Linux) if not available, install them: e.g. Synaptic, apt, dnf, yum ...
# (macOS) https://www.python.org/downloads/macos/

# Install Git:
# (Windows) https://git-scm.com/download/win
# (Linux) https://git-scm.com/download/linux
# (macOS) https://git-scm.com/download/mac

# Set up a virtual environment (pending how to do it in Windows), download 'humble' and its dependencies
# '/home/bluesman/humble_venv' is a example path for the virtual environment
$ python3 -m venv /home/bluesman/humble_venv
$ source /home/bluesman/humble_venv/bin/activate
$ cd /home/bluesman/humble_venv/
$ git clone https://github.com/rfc-st/humble.git
$ cd humble
$ pip3 install -r requirements.txt

# Analyze! :). Linux and Windows examples
$ python3 humble.py -u https://google.com
$ py humble.py -u https://google.com

# Good practice: deactivate the virtual environment after you have finished using 'humble'
$ deactivate

# Activate the virtual environment to analyze again with 'humble'
$ cd /home/bluesman/humble_venv/
$ source /home/bluesman/humble_venv/bin/activate
$ cd humble

# Updating 'humble' (weekly): activate the virtual environment and from 'humble' folder
$ git pull

# Updating 'humble' (Release): activate the virtual environment, download the latest source code file
# and decompress it in the 'humble' folder, overwriting files
https://github.com/rfc-st/humble/releases

Installation & maintenance (Docker)

[!NOTE] Python 3.11 will be used to build the image.

# Install Docker and ensure it is running:
# E.g. (Linux): https://www.kali.org/docs/containers/installing-docker-on-kali/
# E.g. (macOs): https://docs.docker.com/desktop/setup/install/mac-install/
# E.g. (Windows): https://docs.docker.com/desktop/setup/install/windows-install/

# Clone the repository or download the latest release
$ git clone https://github.com/rfc-st/humble.git
https://github.com/rfc-st/humble/releases

# Build the Docker image inside the 'humble' folder: providing the TAG as the latest Release of 'humble' (e.g. 1.64)
# https://github.com/rfc-st/humble/releases (On Windows, this may require running the terminal with admin privileges)
$ cd humble
$ docker build -t humble:1.64 .

# Run the analysis specifying the above TAG, along with the specific options for 'humble':
# '-it' allocates a pseudo-TTY to keep text output clean and formatted.
# '--rm' automatically cleans up and removes the container after it exits.

# (Linux / macOS / Windows)
# E.g. Brief analysis of a URL
$ docker run -it --rm humble:1.64 -u https://google.com -b

# E.g. Detailed analysis of a URL
$ docker run -it --rm humble:1.64 -u https://google.com

# (Optional) Clean up and remove the old image when upgrading:
$ docker rmi humble:1.64

Or if you’d prefer a faster way:

.: Just analyze an URL without exporting results (Universal)

$ docker run --rm ghcr.io/rfc-st/humble:dev -u https://google.com

.: Analyze an URL and export results

# Linux / macOS / Git Bash
$ docker run --rm -v $(pwd):/app ghcr.io/rfc-st/humble:dev -u https://google.com -o pdf
# Windows (PowerShell)
$ docker run --rm -v ${PWD}:/app ghcr.io/rfc-st/humble:dev -u https://google.com -o pdf
# Windows (Command Prompt)
$ docker run --rm -v %cd%:/app ghcr.io/rfc-st/humble:dev -u https://google.com -o pdf

Installation & update (Kali Linux)

[!NOTE] Python 3.11 or higher is required.

# Verify that the output contains 'Homepage: https://github.com/rfc-st/humble'
$ apt show humble

# Install 'humble'
$ sudo apt install humble

# Analyze! :)
$ humble -u https://google.com

# Updating 'humble' (monthly)
$ sudo apt update
$ sudo apt install --only-upgrade humble

Usage

(Windows) $ py humble.py
(Linux)   $ python3 humble.py
(macOS)   $ python3 humble.py

usage: humble.py [-h] [-a] [-b] [-c] [-cicd [GRADE]] [-df] [-e [TESTSSL_PATH]] [-f [FINGERPRINT_TERM]] [-g] [-grd] [-H REQUEST_HEADER] [-if INPUT_FILE] [-l {es}] [-lic]
                 [-o {all,csv,html,json,pdf,txt,xlsx,xml}] [-of OUTPUT_FILE] [-op OUTPUT_PATH] [-p PROXY] [-r] [-s [SKIP_HEADERS ...]] [-u URL] [-ua USER_AGENT] [-v]

'humble' (HTTP Headers Analyzer) | https://github.com/rfc-st/humble | v.2026-08-14

options:
  -h, --help                               show this help message and exit
  -a                                       Print statistics of the performed analysis; if the '-u' parameter is omitted they will be global
  -b                                       Print overall findings; if omitted detailed ones will be printed
  -c                                       Checks URL response HTTP headers for compliance with OWASP 'Secure Headers Project' best practices
  -cicd [GRADE]                            Print analysis for CI/CD processing; optionally, set the minimum required GRADE (E, D, C, B, A, A+)
  -df                                      Do not follow redirects; if omitted the last redirection will be the one analyzed
  -e [TESTSSL_PATH]                        Print only TLS/SSL checks; requires the PATH of testssl (https://testssl.sh/)
  -f [FINGERPRINT_TERM]                    Print fingerprint statistics; if 'FINGERPRINT_TERM' (E.g., 'Google') is omitted the top 20 results will be printed
  -g                                       Print guidelines for enabling security HTTP response headers on popular frameworks, servers and services
  -grd                                     Print the checks to grade an analysis, along with advice for improvement
  -H REQUEST_HEADER                        Adds REQUEST_HEADER to the request; must be in double quotes and can be used multiple times, e.g. -H "Host: example.com"
  -if INPUT_FILE                           Analyzes 'INPUT_FILE': curl's '--dump-header' file or HTTP Archive (HAR) file
  -l {es}                                  Defines the language for displaying analysis, errors and messages; if omitted, will be printed in English
  -lic                                     Print the license for 'humble', along with permissions, limitations and conditions
  -o {all,csv,html,json,pdf,txt,xlsx,xml}  Export the analysis to the specified formats (separated by spaces); 'all' will export to all formats
  -of OUTPUT_FILE                          Exports analysis to 'OUTPUT_FILE'; if omitted the default filename of the parameter '-o' will be used
  -op OUTPUT_PATH                          Exports analysis to 'OUTPUT_PATH'; must be absolute. If omitted the PATH of 'humble.py' will be used
  -p PROXY                                 Use a proxy for the analysis. E.g., 'http://127.0.0.1:8080'. If no port is specified '8080' will be used
  -r                                       Print HTTP response headers and a detailed analysis; '-b' parameter will take priority
  -s [SKIP_HEADERS ...]                    Skips 'deprecated/insecure' and 'missing' checks for the indicated 'SKIP_HEADERS' (separated by spaces)
  -u URL                                   Scheme, host and port to analyze. E.g., https://google.com or https://google.com:443
  -ua USER_AGENT                           User-Agent ID from 'additional/user_agents.txt' file to use. '0' will print all and '1' is the default
  -v, --version                            Checks for updates at https://github.com/rfc-st/humble

examples:
  -u URL -a                                Print statistics of the analysis performed against the URL
  -u URL -b                                Analyzes the URL and prints overall findings
  -u URL -b -o csv                         Analyzes the URL and exports overall findings to CSV format
  -u URL -cicd A                           Analyzes the URL and prints CI/CD results, warning if they do not reach an 'A' grade
  -u URL -l es                             Analyzes the URL and prints (in Spanish) detailed findings
  -u URL -o pdf                            Analyzes the URL and exports detailed findings to PDF format
  -u URL -o html -of test                  Analyzes the URL and exports detailed findings to HTML format and 'test' filename
  -u URL -o html json                      Analyzes the URL and exports detailed findings to HTML and JSON formats
  -u URL -o pdf -op D:/Tests               Analyzes the URL and exports detailed findings to PDF format and 'D:/Tests' path
  -u URL -p http://127.0.0.1:8080          Analyzes the URL using 'http://127.0.0.1:8080' as the proxy
  -u URL -r                                Analyzes the URL and prints detailed findings along with HTTP response headers
  -u URL -s ETag NEL                       Analyzes the URL and skips 'deprecated/insecure' and 'missing' checks for 'ETag' and 'NEL' headers
  -u URL -ua 4                             Analyzes the URL using the fourth User-Agent of 'additional/user_agents.txt' file
  -a -l es                                 Print statistics (in Spanish) of the analysis performed against all URLs
  -f Google                                Print HTTP fingerprint headers related to the term 'Google'

want to contribute?:
  How to                                   https://github.com/rfc-st/humble/blob/master/CONTRIBUTING.md
  Acknowledgements                         https://github.com/rfc-st/humble/#acknowledgements
  References and unit tests                https://humble.readthedocs.io

Advanced usage (Linux)

.: Show only the deprecated headers/protocols and insecure values.

$ python3 humble.py -u https://en.wikipedia.org/ | sed -n '/\[4/,/^\[5/ { /^\[5/!p }' | sed '$d' | sed $'1i \n'

.: Check for HTTP client errors (4XX).

$ python3 humble.py -u https://my.prelude.software/demo/index.pl | grep -A1 -B5 'Note : \|Nota : ' --color=never

.: Analyze multiple URLs and save the results as PDFs; thanks Eduardo for this example!.

$ datasets=('https://facebook.com' 'https://github.com' 'https://www.spacex.com'); for dataset in "${datasets[@]}"; do python3 humble.py -u "$dataset" -o pdf; done

Unit tests

[!IMPORTANT] Before running unit tests and code coverage ensure that the following domains are accessible and that the tests folder has permission to create and delete files and folders:

.: (Linux) - All tests passed successfully (showing all messages in English).

$ cd 
$ cd tests
(Linux)   $ python test_humble.py -l en
(Windows) $ py test_humble.py -l en

.: (Linux) - Code coverage (currently disabled in Windows).

$ cd 
$ cd tests
$ pytest test_humble.py --cov-config=.coveragerc --cov=.. --cov-report=html --tb=no -rA -q -v -W ignore -p no:cacheprovider
$ cd humble_coverage_report
Open the index.html file in a browser.

[!IMPORTANT] After reviewing the code coverage, you can delete the following items from the tests directory keeping the rest:

  • humble_coverage_report folder
  • .coverage file

[!TIP] Parameters used in pytest and pytest-cov:

  • --cov-config=.coveragerc: Specifies the coverage configuration file
  • --cov=..: Specifies what code to measure coverage for
  • --cov-report=html: Defines the coverage report format
  • --tb=no: Does not show tracebacks for failed tests
  • -rA: Show all extra test summary info
  • -q: Quiet mode (during the analysis)
  • -v: Verbose mode (after the analysis)
  • -W ignore: Ignore all warnings during test execution
  • --p no:cacheprovider: Prevents creation of .pytest_cache

Global humble.skip

If you need to persistently exclude certain HTTP response headers from being analyzed across all analyses, without specifying the -s parameter every time, you can adjust the provided humble.skip file.

AI

Skill: humble-header-analyst

Purpose: Expert-level parsing and remediation of humble HTTP security-header reports - triaging and fixing missing, deprecated, insecure, duplicated, empty, or fingerprinting headers, and explaining security-header grades.

Turn the comprehensive analysis generated by humble into a senior-level security debrief. Use it two ways:

Option 1 - Any chat interface (manual)

Works anywhere, including chat UIs with no agent framework (e.g. ChatGPT, Gemini, Claude.ai):

  1. Paste the contents of SKILL.md into your chat (or set it up as a custom Persona).
  2. Run an analysis with humble, including response headers, in English .txt. Ex: python3 humble.py -u -o txt -r
  3. Feed the resulting .txt analysis file to your AI.

Option 2 - Agent workflows

OpenAgentSkill / skills CLI (installs into Claude Code, Codex, Cursor, and 70+ agents):

$ npx skills add rfc-st/humble

Codex prompt:

Install the humble-header-analyst skill from https://raw.githubusercontent.com/rfc-st/humble/master/humble-header-analyst/SKILL.md - read it first, install only the files this workspace needs, and summarize any required setup before using it.

Claude Code prompt:

Add humble-header-analyst as a Claude Code skill from https://raw.githubusercontent.com/rfc-st/humble/master/humble-header-analyst/SKILL.md - read and follow its instructions.

Cursor prompt:

Turn the humble-header-analyst skill from https://raw.githubusercontent.com/rfc-st/humble/master/humble-header-analyst/SKILL.md into a reusable Cursor project rule or agent instruction. Preserve the core workflow and keep the rule scoped to relevant tasks.

Example output

Once you’ve completed the steps above, humble’s raw analysis:

becomes a structured security debrief (tested on Claude Opus 4.8):

Quality, style and security tools

humble has enabled the following workflows:

  • Bandit
  • CodeQl
  • Dependabot
  • vulture

It is also reviewed with the following extensions in Visual Studio Code:

  • Ruff
  • SonarQube for IDE
  • Sourcery

And is regularly audited manually using the following tools (for each of them, I indicate how I use them):

  • Bandit: bandit -r /home/bluesman/humble/humble.py --severity-level high
  • Codeaudit: codeaudit filescan humble.py --n
  • Complexipy: complexipy . --exclude /home/bluesman/humble/tests
  • opengrep: opengrep scan --taint-intrafile --config /home/bluesman/opengrep-rules/python humble.py
  • pip-audit: pip-audit -r requirements.txt
  • pyinstrument: python -m pyinstrument -r html humble.py -u https://google.com
  • radon: radon cc humble.py -s -a
  • Refurb: refurb humble.py --python-version 3.11
  • ShellCheck: shellcheck internal/releases.sh internal/security.sh
  • vulture: vulture --min-confidence 60 humble.py

Example of one of these audits:

Checks: enabled headers

Check this file.

Checks: missing headers

Check this file.

Checks: fingerprint headers

Check this file.

Checks: deprecated headers/protocols and insecure values

Check this file.

[!NOTE] humble tries to be strict: both in checking HTTP response headers and their values; some of these headers may be experimental and you may not agree with all the results after analysis.

And that’s OK! :smiley:; you should never blindly trust the results of security tools: there should be further work to decide whether the risk is non-existent, potential or real depending on the analyzed URL (its exposure, environment, etc).

Checks: empty values

Any HTTP response header.

Guidelines included to enable security HTTP headers

  • Amazon Web Services
  • Angular
  • Apache HTTP Server
  • Cloudflare
  • LiteSpeed Web Server
  • Microsoft Internet Information Services
  • Nginx
  • Node.js
  • Spring
  • WordPress

To-Do

  • [ ] Add more Header/Value checks (only security-oriented)

Further reading

  • Web browsers’ experimental features, roadmaps, technology previews and trials: Google Chrome Microsoft Edge Mozilla Firefox Opera Safari

  • Similar tools on GitHub: ‘HTTP Headers Analyze’ ‘HTTP Headers Secure’ ‘HTTP Headers Security’ OWASP Secure Headers Project

  • References and standards: Can I use? Mozilla Developer Network World Wide Web Consortium

  • Additional information: Common response headers Security Headers (HTTP response header analyzer) Scott Helme (Security Researcher)

Contribute

  • Read this first!.
  • Report a Bug.
  • Create a Feature request.
  • Report a Security Vulnerability.
  • Send me your suggestions: [email protected]
  • Or use that email to tell me about integrations of this tool in others!
  • And to recommend me a good Blues! :sunglasses:

Thanks for downloading humble, for trying it and for your time!.

Acknowledgements

  • All the authors/teams of these quality, style and security tools: you rock :metal:!.
  • 1nabillion for this.
  • Aniket Navlur for this gem.
  • Azathothas for reporting this bug.
  • bulaktm for this suggestion.
  • confuciussayuhm for this suggestion.
  • cr4zyfish for some of these suggestions.
  • danterolle for this.
  • David for believing in the usefulness of this tool.
  • Eduardo for the first Demo and the example “(Linux) - Analyze multiple URLs and save the results as PDFs”.
  • gl4nce for this suggestion.
  • İDRİS BUDAK for reporting the need to this check.
  • ilLuSion-007 for this.
  • javelinsoft for this.
  • Julio for testing on macOS and for this suggestion.
  • kazet for this suggestion.
  • manuel-sommer for this, this and this!.
  • mfabbri for this.
  • mgrottenthaler for this, this and this!.
  • MichaelMVS for this.
  • MikeAnast for several suggestions.
  • multipartninja for this and this.
  • n3bojs4, ehlewis and dkadev for this and this.
  • n1j0 for this and this.
  • Sophie Brun for keeping ‘humble’ updated in Kali Linux and for this.
  • stanley101music for this, this and this!.
  • vincentcox for this and this.

License

MIT © 2020-2026 Rafa ‘Bluesman’ Faura ([email protected]) Original Creator - Rafa ‘Bluesman’ Faura ([email protected])

View this README on GitHub

推荐工具

换一个关键词,或者移除筛选条件。

安装

npx skillfish add rfc-st/humble