Security headers are instructions your app sends with every page, telling the browser what it may and may not do. They are medium severity on their own, and they are the first thing an outside scan looks at.
What to check
- HTTPS redirect
- Requesting http:// returns a permanent redirect to https://, with nothing served in the clear.
- Strict-Transport-Security
- Tells the browser to use HTTPS only, for at least a year.
- Content-Security-Policy
- Limits where scripts can load from, which blunts cross-site scripting.
- X-Content-Type-Options
- Set to nosniff so the browser does not guess file types.
- Frame protection
- Stops other sites putting your pages in a frame to trick a click.
- Referrer-Policy
- Stops full URLs, which can carry tokens, leaking to other sites.
Add them
Add these response headers to every route in production: Strict-Transport-Security with max-age=31536000 and includeSubDomains; X-Content-Type-Options: nosniff; Referrer-Policy: strict-origin-when-cross-origin; frame-ancestors none (or X-Frame-Options: DENY); and a Content-Security-Policy that allows scripts only from this site and the third parties the app really loads. Make plain HTTP redirect permanently to HTTPS. Tell me every third-party domain you had to allow and why.
Check it
Load your live site, open the browser developer tools, and read the response headers on the main document. Every header above should be there.