Build and test HTTP security headers with live scoring
Controls which resources can load. The most powerful XSS defense.
Forces HTTPS, prevents protocol downgrade attacks.
Prevents your site from being embedded in iframes (clickjacking defense).
Prevents browsers from MIME-sniffing content types.
Controls how much referrer info is shared when navigating away.
Controls which browser features (camera, mic, geolocation) the site can use.
Legacy XSS filter (mostly replaced by CSP, but still useful).