What security headers are
Along with the page, the server sends the browser service HTTP headers. Some of them turn on the browser's built-in protection: they forbid opening the site without encryption, running third-party scripts or embedding the page in other sites. You set them up once, and they protect visitors from entire classes of attacks.
How to improve your grade
- Start with the easy ones:
X-Content-Type-Options: nosniff,X-Frame-Options: SAMEORIGINandReferrer-Policy: strict-origin-when-cross-origindon't affect how the site works. - Enable HSTS once you are sure the whole site and its subdomains work over HTTPS.
- Roll out Content-Security-Policy gradually: first in
Content-Security-Policy-Report-Onlymode to see what would be blocked. - Hide the web server and PHP versions:
ServerTokens Prodin Apache,server_tokens offin nginx,expose_php = Offin PHP.
Ready-made lines for Apache are added by the .htaccess generator — the “Security headers” option.