Хостинг в Україні від Mevcore

Security headers

Grade a site’s HTTP security headers — HSTS, CSP, X-Frame-Options and more — with explanations and advice.

Fetching headers…

What security headers are

Along with the page, the server sends the browser service HTTP headers. Some of them turn on the browser's built-in protection: they forbid opening the site without encryption, running third-party scripts or embedding the page in other sites. You set them up once, and they protect visitors from entire classes of attacks.

How to improve your grade

  • Start with the easy ones: X-Content-Type-Options: nosniff, X-Frame-Options: SAMEORIGIN and Referrer-Policy: strict-origin-when-cross-origin don't affect how the site works.
  • Enable HSTS once you are sure the whole site and its subdomains work over HTTPS.
  • Roll out Content-Security-Policy gradually: first in Content-Security-Policy-Report-Only mode to see what would be blocked.
  • Hide the web server and PHP versions: ServerTokens Prod in Apache, server_tokens off in nginx, expose_php = Off in PHP.

Ready-made lines for Apache are added by the .htaccess generator — the “Security headers” option.

What should we call you?

Enter your name before starting the chat.

Hello! Type your question and an agent will reply as soon as possible.
Rate the agent’s reply