HeaderProof is intended for authorized security testing only.
If you find a bug in the scanner itself, open a GitHub issue with:
- version or commit hash
- command used
- sanitized input sample
- expected behavior
- actual behavior
Do not include live target secrets, credentials, cookies, private URLs, or exploit evidence from third-party systems.
Only scan assets where you have explicit permission. The tool is designed to use low-impact requests, but operators remain responsible for scope, rate, and program policy.