All workflows
OpenAI logoGmail logo

Weekly security header review of your own sites

Requests each site you list once a week, reports the security headers a visitor's browser is not getting, and emails what to fix.

Every Monday at 08:002 apps2 steps

Apps it connects

Authenticate each one once and the workflow is ready to run.

What it does

The integration steps this workflow runs, in the order it first runs them.

  1. 1OpenAIQuery model
  2. 2GmailSend

How it works

Everything the template sets up, and what to fill in before the first run.

Every Monday morning this reads the security headers on the websites you list and emails you a summary of what is missing - the review a small team means to do and never gets round to.

It is a passive check of sites you own, not a scanner. Each site gets one ordinary page request, exactly what a visitor's browser makes, and only the response to that request is read. Nothing is probed, no paths are guessed, no inputs are tried, and no address other than the ones you list is contacted. Put only sites you are responsible for in the list.

Five headers are checked by name: Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options and Referrer-Policy. That list is fixed - the workflow names the headers it reads rather than taking them from a step - so if you want a sixth, add another check alongside the five.

The request starts at the plain http address of each site, which is why one request is enough to show two things at once: whether a visitor arriving over http is sent on to https, and what headers the page they land on actually sends. The Server header is reported verbatim, so a banner naming a version number is visible.

AI then explains, for each site, what a missing header does and the change to make in your web server or CDN. It is asked not to judge how exploitable anything is and not to invent findings - the readings in the email are the measurements, and they are sent even if the write-up fails.

A site that cannot be reached is listed under 'could not be checked' with the reason, and never stops the remaining sites being read. Its address is stripped out of the failure message before it goes in the email.

Set it up by filling in two steps: 'siteList' with your sites, one per line, and 'reportEmail' with the address the summary goes to.

securityhttpheadershstscspgmailopenaiweekly

Start from a workflow that already works.

Add "Weekly security header review of your own sites" to your workspace, connect its apps, and make it yours. No credit card required.

Free plan available · No credit card required