Mastra
A TypeScript agent framework covering agents, workflows, tools, memory, and evals, with an Apache 2.0 core and an optional hosted platform.
Open core. Framework free under Apache 2.0; hosted platform has a free starter tier, a flat rate team tier, and custom enterprise, with consumption metering on top of included allowances. Self-hosted enterprise is quoted individually.
Open source
Appears in 1 guide
Where it ranks
Guides that include Mastra.
Security headers
What Mastra's website sends to your browser.
Scanned 2026-08-25. Grade headers F, scoring 20 out of 100.
−
No Content-Security-Policy, so no defence in depth against cross-site scripting
+
Strict-Transport-Security is set
−
No X-Content-Type-Options, so MIME sniffing is not disabled
−
No X-Frame-Options and no CSP frame-ancestors, so clickjacking is possible
−
No Referrer-Policy, so full URLs may leak to third parties
−
No Permissions-Policy, so powerful browser features are not restricted
−
No Cross-Origin-Opener-Policy
−
No Cross-Origin-Resource-Policy
−
Server version or framework disclosed via Server/X-Powered-By
This is one narrow, automated check of the HTTP response headers on the vendor's own website. It says nothing about how the product itself is built, how it stores your data, or whether it has ever been audited. A good grade here is a small signal that somebody was paying attention.