Security header guides

From a failing header
to a tested fix.

What each security header protects against, how to roll it out without breaking your site, and configuration we ran on real servers before publishing it.

Headers in the grade
6
Heaviest header: CSP
25/100
Guides published
2

01 / The headers grade

Six headers.
One score out of 100.

Each header earns its full weight when it passes, half when WebSec0 flags a weakness, and nothing when it is missing. Start with the heaviest one.

  1. 25ptsContent-Security-PolicyLimits where scripts and other resources load from. Server guides: Nginx.Read the guide
  2. 20ptsStrict-Transport-SecurityKeeps browsers on HTTPS for every later visit.Planned
  3. 15ptsX-Frame-OptionsStops other sites from framing your pages.Planned
  4. 15ptsReferrer-PolicyControls how much of your URLs leaks to other sites.Planned
  5. 15ptsPermissions-PolicySwitches off browser features you do not use.Planned
  6. 10ptsX-Content-Type-OptionsStops browsers from guessing content types.Planned

02 / How we write them

Fewer opinions.
More evidence.

01

Tested before published

Every server snippet is run in a container on the versions named in the guide, and its headers checked with curl, error pages included.

Written and tested by Joshua Martinelle.

02

Aligned with the scanner

Each guide explains exactly what WebSec0 checks and how it scores, so the fix you apply is the one the report asks for.

03

Sourced and dated

Claims link to specifications, MDN and server documentation. Browser support and server versions are rechecked when we update a guide.

Not sure where to start?

Scan first. Fix what fails.

The report links each failing header to its guide.

Scan your site