LINTEL
mind the headers

Grade a site's security headers.

An offline grader for the security headers of an HTTP response: it shows which protections are in place, which are undercut, and which are missing — and never calls a site secure.

Python 3.10+PyQt6 network never159 testsMIT

Why

A handful of response headers decide whether a browser will fall back to plain HTTP, run injected script, let your page be framed, or hand your cookies to any script on it. They are cheap to set and easy to forget.

Whether they are present is a yes-or-no fact sitting in the response, if you know which to look for. Lintel looks, and shows the shape of a site's protection before you have read a word.

What it draws. The coverage grid — seven defences as tiles, green, amber or red, so a wall of green and a scatter of red are telling you different things at a glance.
Lintel reading two samples

The reader on two of its bundled samples.

What it checks

SignalWhat trips it
HSTSa long max-age, ideally with preload
CSPenforced, without unsafe-inline or a wildcard
MIME sniffingX-Content-Type-Options: nosniff
ClickjackingX-Frame-Options or CSP frame-ancestors
Referrera policy that does not leak the full URL
CookiesSecure, HttpOnly and a sound SameSite
Disclosureversion leaks and deprecated headers

The honest part

Lintel grades the headers you paste and nothing else. It cannot see your TLS configuration, whether a CSP matches your markup, cookies set later by script, or what a proxy added or stripped. A high grade means the headers are well configured, not that a site is secure.

Install

git clone https://github.com/at0m-b0mb/Lintel-HTTP-Headers.git
cd Lintel-HTTP-Headers
python3 -m pip install -r requirements.txt

python3 -m lintel                      # the window
python3 -m lintel samples/             # the command line
python3 -m pytest -q                   # 159 tests

The engine and the command line need no dependencies at all — only the standard library. PyQt6 is required solely for the window.

One of seven readers