DrHeader Integration with DefectDojo
DrHeader is an open-source HTTP security headers auditing tool developed by Santander UK Security Engineering that scans web application responses to identify missing or misconfigured security headers such as Content-Security-Policy, X-Frame-Options, Strict-Transport-Security, and other headers critical for protecting against XSS, clickjacking, and information disclosure attacks. The tool integrates seamlessly with CI/CD pipelines and aligns with OWASP Application Security Verification Standard (ASVS) 4.0 to provide automated security header compliance checks through both CLI and Python library interfaces with customizable YAML-based security policies.
Data Granularity: What Gets Imported
The following fields are captured from DrHeader results and surfaced in DefectDojo findings:
| Field | Source | Notes |
|---|---|---|
| Title | Finding name from the scan | Matched to the tool's own naming |
| Severity | Critical / High / Medium / Low / Info | Mapped from the tool's own severity scale |
| Description | Finding detail from the report | Includes what the issue is and why it matters |
| Mitigation | Remediation guidance | Where the tool provides it |
Importing Into DefectDojo
Use the DefectDojo import API to create a new Test under the relevant Engagement for your product. The request body:
{
"scan_type": "DrHeader",
"engagement": "<engagement-id>",
"file": "results.json"
}