Reads security headers and CSP line by line in your config file and names the lines that silently do
137
Reads security headers and CSP line by line in your config file and names the lines that silently do nothing: retired headers, keywords missing their quotes, directives the browser throws away.
docker run --rm -v "$PWD":/work getreadystack/security-headers-csp-lint /work/file
The same 28 rules as the VS Code extension, in a container. Mount a folder on /work.
--rules lists every ruledocker run --rm -e READYSTACK_LICENSE=<key> -v "$PWD":/work getreadystack/security-headers-csp-lint --dir /work --ci
Application security consultants doing secure code review bill roughly $120 to $275 an hour, and a security-header and CSP review is a one-to-two hour job per site.
Claude Code · Cursor · Windsurf · any MCP client - add to your MCP config:
{ "mcpServers": { "security-headers-csp-lint": { "command": "npx", "args": ["-y", "@readystack/security-headers-csp-lint", "--mcp"] } } }
Tools: check_text and check_file (free) · check_dir (licence; the full sweep is free for 7 days). The agent gets every finding with the line number.
- name: Security Headers Lint - CSP and Dead Headers
run: npx -y @readystack/security-headers-csp-lint --dir . --ci
(container: docker run --rm -v "$PWD:/work" getreadystack/security-headers-csp-lint --dir /work --ci)
Try the full run free for 7 days — no key needed. Then one licence, 7-day refund, no questions. Set READYSTACK_LICENSE=<key> or run --license <key> once.
Content type
Image
Digest
sha256:9a66ff7b9…
Size
46.1 MB
Last updated
about 5 hours ago
docker pull getreadystack/security-headers-csp-lint