Let's talk about your project

Security headers

HTTP headers the server sends with its responses that tell the browser how the page should behave securely, such as HSTS, content security policy, framing and content-type rules.

  1. 01

    Why it matters

    These headers block a significant share of attacks at browser level, such as the site being secretly framed inside another page, content types being misinterpreted or foreign scripts running. They are usually easy to add and need no change to the application; they are among the first things checked in audits.

  2. 02

    Example

    A security scorecard shows that a site is missing its framing and content-type headers. Adding two lines to the hosting settings sends the headers on every page and the scorecard turns green.

  3. 03

    Common mistake

    Adding headers in their strictest form without testing. A misconfigured content security policy in particular breaks legitimate scripts such as payment, analytics or chat; try it in report-only mode first.

  4. 04
Let's begin

Let's talk about your project.

Tell us what you need; we will define the scope together.