# cSPY - SecurityHeader Scanner

> Advanced security header scanner with CSP analysis, multi-engine scoring, actionable recommendations, and PDF report export. Zero external requests — all analysis runs locally.

Canonical page: [https://chrome-stats.com/d/cspy](https://chrome-stats.com/d/cspy)

## Overview

- **ID:** `cspy`
- **Platform:** Firefox
- **Type:** Firefox add-on
- **Status:** Available
- **Publisher:** VaultOcean
- **Category:** web-development,privacy-security,alerts-updates
- **Daily users:** 34
- **Weekly downloads:** 5
- **Rating:** 5.00 / 5 (1 ratings)
- **Version:** 2.0.0
- **Last updated:** 2026-06-05
- **First published:** 2025-06-25
- **Size:** 135 KB
- **Data as of:** 2026-09-11
- **Store listing:** [Firefox Add-ons Store](https://addons.mozilla.org/firefox/addon/cspy/)
- **Privacy policy:** [https://addons.mozilla.org/firefox/addon/cspy/privacy/](https://addons.mozilla.org/firefox/addon/cspy/privacy/)

## Description

CSPy is a professional-grade browser extension that audits HTTP security headers in real time. Built for developers, penetration testers, and security researchers.

WHAT IT DOES
• Scans every HTTP response header on any website
• Deep Content-Security-Policy (CSP) directive-by-directive analysis
• Detects missing, weak, or misconfigured headers (HSTS, X-Frame-Options, CORS, Referrer-Policy, Permissions-Policy, COOP, COEP, CORP, cookies)
• Grades security posture from A+ to F with a 0–100 score

MULTI-ENGINE CONSENSUS
• Three independent scoring engines: CSPy, Google CSP Evaluator, and Mozilla Observatory
• Cross-validates results — when engines agree, confidence is high

ACTIONABLE RECOMMENDATIONS
• Every finding includes a plain-English fix
• Copy-paste server configurations for nginx, Apache, Express, Django, Cloudflare Workers, and Vercel
• Prioritised by severity — fix what matters first

EXPORT &amp; REPORTING
• Professional PDF report with cover page, executive summary, recommendations, and raw headers
• HTML, JSON, and Markdown (bug bounty) export formats
• Ready for stakeholder presentations or HackerOne/Bugcrowd submissions

ADDITIONAL TOOLS
• Auto-generate a working CSP from observed network traffic
• Infrastructure fingerprinting (CDN, WAF, hosting, framework detection)
• DOM audit (missing SRI, mixed content, unsafe iframes)
• Per-request security grading for all sub-resources

PRIVACY
• Zero external network requests — all analysis runs entirely in your browser
• No data collection, no telemetry, no accounts
• Open-source analysis engine

Built by VaultOcean — <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/b3fd5d90cac47cf6acadf04a510f0c09b576c4ce5ef71918afe5fc862bebc627/https%3A//vaultocean.com" rel="nofollow">https://vaultocean.com</a>

## Rankings

- #19,384 — Overall
- #24 — ad spy
- #35 — security
- #67 — header
- #96 — analysis
- #104 — scan

## Permissions and access

### Permissions

- `webRequest`
- `tabs`
- `storage`
- `cookies`
- `notifications`
- `scripting`
- `downloads`

### Host permissions

- `<all_urls>`

### Content script matches

- `<all_urls>`

## Safety

- **Risk impact:** High risk impact
- **Risk likelihood:** Moderate risk likelihood

### Analysis details

- Grants access to browser tabs, which can be used to track user browsing habits and history, presenting a privacy concern.
- This extension has low user count. Unpopular extensions may not be stable or safe.

> Some risk analysis details are omitted from this free response. [Upgrade to view the full analysis](https://chrome-stats.com/pricing).

## Similar extensions and apps

- [CSP Evaluator ext](https://chrome-stats.com/d/csp-evaluator-ext) — 3 users
- [CSPTool](https://chrome-stats.com/d/csptool) — 1 users
- [I Hate Security Headers!](https://chrome-stats.com/d/i-hate-security-headers) — 1 users
- [Security Header Grader](https://chrome-stats.com/d/security-header-grader) — 2 users
- [Content Security Policy (CSP) Generator](https://chrome-stats.com/d/csp-generator) — 588 users, 4.00 / 5
- [HTTP Header Security Auditor](https://chrome-stats.com/d/http-header-security-auditor) — 2 users
- [CSP Content Security Policy Generator](https://chrome-stats.com/d/content-security-policy-gen) — 257 users, 3.40 / 5
- [cSPY - SecurityHeader Scanner](https://chrome-stats.com/d/vaultocean-header-scanner) — 34 users, 5.00 / 5
- [SecuriScan – Web Analyzer](https://chrome-stats.com/d/securiscan-web-analyzer) — 2 users
- [CSP Checker](https://chrome-stats.com/d/csp-checker) — 17 users
- [ssec-seo Scanner](https://chrome-stats.com/d/ssec-seo-scanner) — 1 users
- [CSP Evaluator](https://chrome-stats.com/d/csp-evaluator) — 377 users, 4.00 / 5

---

Source: [Chrome-Stats](https://chrome-stats.com/d/cspy)
