Author

Joshua Martinelle

Security engineer at Tenable

Joshua Martinelle is a security engineer at Tenable and a web security researcher. Since 2020 he has disclosed more than 60 CVEs, 15 of them rated critical, in software such as Gitea, Langflow, Flowise, Nginx UI and dozens of WordPress plugins.

Many of those findings are cross-site scripting, SQL injection and broken authentication: the bugs that security headers like Content-Security-Policy are meant to contain. He created WebSec0 to make configuration checks clearer, and writes and tests these guides.

Portrait of Joshua Martinelle

01 / Track record

Findings you can check.

Every figure links to its public source.

02 / Guides

Written and tested by Joshua.

  1. Content-Security-Policy · NginxAdd a Content-Security-Policy header in Nginx, test it in report-only mode, keep it on every location and error page, and add nonces or hashes. Tested configs.
  2. Content-Security-PolicyContent-Security-Policy tells the browser which scripts, styles and frames a page may load. Learn the key directives, strict nonce policies and a safe rollout.