An offline grader for the security headers of an HTTP response: it shows which protections are in place, which are undercut, and which are missing — and never calls a site secure.
A handful of response headers decide whether a browser will fall back to plain HTTP, run injected script, let your page be framed, or hand your cookies to any script on it. They are cheap to set and easy to forget.
Whether they are present is a yes-or-no fact sitting in the response, if you know which to look for. Lintel looks, and shows the shape of a site's protection before you have read a word.
The reader on two of its bundled samples.
| Signal | What trips it |
|---|---|
| HSTS | a long max-age, ideally with preload |
| CSP | enforced, without unsafe-inline or a wildcard |
| MIME sniffing | X-Content-Type-Options: nosniff |
| Clickjacking | X-Frame-Options or CSP frame-ancestors |
| Referrer | a policy that does not leak the full URL |
| Cookies | Secure, HttpOnly and a sound SameSite |
| Disclosure | version leaks and deprecated headers |
Lintel grades the headers you paste and nothing else. It cannot see your TLS configuration, whether a CSP matches your markup, cookies set later by script, or what a proxy added or stripped. A high grade means the headers are well configured, not that a site is secure.
git clone https://github.com/at0m-b0mb/Lintel-HTTP-Headers.git
cd Lintel-HTTP-Headers
python3 -m pip install -r requirements.txt
python3 -m lintel # the window
python3 -m lintel samples/ # the command line
python3 -m pytest -q # 159 tests
The engine and the command line need no dependencies at all — only the standard library. PyQt6 is required solely for the window.