All integrations

Humble Report Integration with DefectDojo

Humble Report Integration with DefectDojo

Humble is an open source, security-oriented HTTP headers analyzer written in Python and maintained by Rafa Faura (rfc-st on GitHub). Given a URL, it requests the page and reviews the response headers, reporting missing security headers, headers that fingerprint the server or framework, deprecated headers and insecure values, and headers sent with empty values. It can export its analysis in several formats, including JSON, which DefectDojo imports with the Humble Json Importer scan type.

Humble Report Integration with DefectDojo

We use Humble because header hardening is easy to get right once and easy to lose with the next CDN change or framework upgrade. A Humble report tells us what one site is sending today. Importing it into DefectDojo turns each missing or problematic header into a Finding on that site's Asset, tied to the URL, with an owner and an SLA. When a team adds a missing header and we reimport, the finding closes on its own.

Why Humble Matters

Response headers are a cheap layer of defense, and they are often the first thing an external assessment points out.

  • Missing headers such as Content-Security-Policy, Strict-Transport-Security, or X-Frame-Options leave browsers without protections the application could have asked for.
  • Fingerprinting headers disclose server software or platform details that help an attacker pick targets.
  • Deprecated headers and insecure values are easy to miss because they look like they are doing something.
  • Humble is fast and lightweight, so it fits in a pipeline step or a scheduled check against many sites.
  • On its own, the report is a snapshot for one URL. Nothing tracks whether last month's missing header was ever added.

Advantages of This Integration

What DefectDojo adds to Humble reports:

  • One finding per header issue. Each entry in the missing, fingerprint, deprecated, and empty value sections becomes its own Finding, so they can be assigned and closed independently.
  • Endpoint attached. Every finding carries the analyzed URL as its endpoint, which ties header issues to the right site.
  • Closure through reimport. Reimporting a new report into the same Test mitigates headers that are no longer flagged and adds anything new.
  • SLAs and ownership. Header findings import at Medium, so they fall under your Medium SLA and can be pushed to Jira for the team that owns the web server or CDN configuration.
  • Clean results stay clean. Sections where Humble reports nothing to flag produce no findings.
  • Header issues in context. Findings sit on the same Asset as DAST, SAST, and dependency results for the site, so a missing Content-Security-Policy can be weighed next to any cross-site scripting reports for the same application instead of being reviewed in isolation.

How This Integration Works

DefectDojo imports Humble reports with the Humble Json Importer scan type.

1. Produce a JSON report. Run Humble against a URL and export JSON:

python3 humble.py -u https://www.example.com -o json

Humble writes the export file to its own directory unless you pass an absolute export path with -op. The parser reads the URL from the [0. Info] section and findings from these sections: [1. Missing HTTP Security Headers], [2. Fingerprint HTTP Response Headers], [3. Deprecated HTTP Response Headers/Protocols and Insecure Values], and [4. Empty HTTP Response Headers Values].

2. Import it. In the UI, open the Engagement, choose Import Scan Results, select Humble Json Importer, and upload the file. To automate it in Community Edition or DefectDojo Pro:

curl "https://YOUR_INSTANCE/api/v2/import-scan/" 
  -H "Authorization: Token $DD_API_TOKEN" 
  -F "scan_type=Humble Json Importer" 
  -F "file=@humble-report.json" 
  -F "product_name=marketing-site" 
  -F "engagement_name=Header Checks" 
  -F "auto_create_context=true"

DefectDojo Pro users can run the same import with Universal Importer:

universal-importer import 
  --defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/" 
  --scan-type "Humble Json Importer" 
  --report-path "./humble-report.json" 
  --product-name "marketing-site" 
  --engagement-name "Header Checks" 
  --auto-create-context

3. Reimport after changes. When a team updates header configuration, rerun Humble and send the report to /api/v2/reimport-scan/ against the same Test so fixed headers are mitigated.

Data Granularity: What Gets Imported

DefectDojo Field Source in Humble Report Notes
Title Section entry Missing header: X, Available fingerprint:X, Deprecated header: X, or Empty HTTP response header: X
Severity Fixed Always Medium
Description Section entry A fixed sentence per section naming the header, for example "This security Header is missing: X"
Endpoint [0. Info] URL The analyzed URL, on every finding
Finding type Dynamic Humble requests a live URL
Deduplication Hashcode Title only

Entries that read "Nothing to report, all seems OK!" are skipped. Each entry is imported as written by Humble, so annotations such as "(Deprecated Header)" or "(Recommended Values)" become part of the title and help explain why the header was flagged. Other report sections, such as the raw response headers and browser compatibility, are not imported.

Use Cases

Release checks for public sites: A web team runs Humble against staging after each deployment and reimports the report. A header that disappears because of a configuration change shows up as a new Medium finding before the release goes out.

CDN and proxy changes: When the platform team moves a site behind a new CDN, fingerprinting headers from the new provider often appear. Importing a Humble report right after cutover makes those visible and assignable.

Baseline hardening across many sites: A security team scans each public site and imports each report into that site's Asset. Leadership sees which properties still lack Content-Security-Policy or HSTS, by owner.

External assessment prep: Before a pentest or customer security review, a team clears its open Humble findings so testers spend their time on application logic instead of header hygiene.

Operational Tips

  • Deduplication uses the title only, and titles do not include the URL. Put each site in its own Asset, or use one Engagement per site with deduplication_on_engagement=true, so one site's missing header is not marked a duplicate of another's.
  • Every finding imports at Medium. Adjust severity in DefectDojo for headers that matter less for a given site, such as fingerprinting headers on an internal tool.
  • The parser reads Humble's JSON sections by their exact names. After upgrading Humble, test an import before relying on it in a pipeline, since a renamed section will cause the import to fail.
  • Use one Test per URL and reimport into it, so mitigation history stays clear.
  • Risk-accept headers that are intentionally absent, for example a cross-origin policy a site cannot adopt yet, with an expiration date so they come back for review.
  • Tag imports with the environment (tags=staging or tags=production) when you scan both.