BETA · GateTest is in active polish ahead of public launch. Some flows are rough. Found a bug? hello@gatetest.ai — we're reading every message.
Web & UX module

Web Headers

CSP/HSTS/XFO/CORS misconfig across Next.js, Vercel, Netlify, Express, Fastify, nginx.

One of 104 modules in the GateTest scan suite. Catches the issue before it reaches code review, and on paid tiers opens a pull request with the fix already written.

Example finding from the webHeaders module

CSP missing — defaults to inline-everything

Why we catch it

Surfacing the user-visible problems static analysis usually pretends don't exist.

The Web Headers module sits in this category alongside 6 related modules. Together they form one of the layers of a GateTest scan — checks fire in parallel, findings cluster by root cause, and on paid tiers the AI auto-fix loop reads each finding, writes the fix, validates against the scanner, and opens a PR.

How GateTest covers web headers

  • Runs in every scan. Included on the Full ($99), Scan + Fix ($199), and Forensic Scan ($399) tiers. No additional configuration.
  • Free CLI. npm i -g gatetest && gatetest --module webHeaders against any local repo. No paywall on the scanning itself.
  • AI auto-fix PR. Scan + Fix tier opens a pull request with the fix, a regression test, and a pair-review by a second Claude. Forensic Scan tier adds per-finding diagnosis and cross-finding attack-chain correlation.
  • Honest confidence rating. Findings come with high / medium / low confidence so noisy patterns don't block the gate. The confidence-calibrator trainer reads customer suppressions and tightens rules over time.

Scan your repo for web headers

Free preview of the headline findings. Pay per scan — no subscription.

Frequently asked questions

What does the Web Headers module catch?

CSP/HSTS/XFO/CORS misconfig across Next.js, Vercel, Netlify, Express, Fastify, nginx. Example finding: CSP missing — defaults to inline-everything

Does GateTest fix Web Headers issues automatically?

Yes — on the Scan + Fix tier ($199) and Forensic Scan tier ($399), Claude reads the finding, writes the fix, validates against the scanner, writes a regression test, and opens a pull request for your review.

Which tiers include the Web Headers module?

The Full tier ($99), Scan + Fix tier ($199), and Forensic Scan tier ($399) include all 104 modules including Web Headers. The Quick tier ($29) only includes 4 essential modules.

Can I run the Web Headers module from the CLI for free?

Yes — install with `npm i -g gatetest` and run `gatetest --module webHeaders` against any local repository. Paid tiers add AI auto-fix and the cross-finding correlation work.

Related modules in Web & UX

Comparing GateTest to another tool?