First steps

HTTPS and security headers in ten minutes

The headers every browser respects, what each one prevents, and a prompt that adds them in one pass.

6 min readChecks: TR-1, TR-2

Security headers are instructions your app sends with every page, telling the browser what it may and may not do. They are medium severity on their own, and they are the first thing an outside scan looks at.

What to check

HTTPS redirect
Requesting http:// returns a permanent redirect to https://, with nothing served in the clear.
Strict-Transport-Security
Tells the browser to use HTTPS only, for at least a year.
Content-Security-Policy
Limits where scripts can load from, which blunts cross-site scripting.
X-Content-Type-Options
Set to nosniff so the browser does not guess file types.
Frame protection
Stops other sites putting your pages in a frame to trick a click.
Referrer-Policy
Stops full URLs, which can carry tokens, leaking to other sites.

Add them

Paste into your AI coding tool
Add these response headers to every route in production: Strict-Transport-Security with max-age=31536000 and includeSubDomains; X-Content-Type-Options: nosniff; Referrer-Policy: strict-origin-when-cross-origin; frame-ancestors none (or X-Frame-Options: DENY); and a Content-Security-Policy that allows scripts only from this site and the third parties the app really loads. Make plain HTTP redirect permanently to HTTPS. Tell me every third-party domain you had to allow and why.

Check it

Load your live site, open the browser developer tools, and read the response headers on the main document. Every header above should be there.

All 77 checks, ranked by severity

The free checklist has every check in this guide and the rest, each with a fix prompt and a deadline.

Get the free checklist