What Are HTTP Security Headers?
HTTP security headers are directives sent by web servers that instruct browsers how to handle content. They provide an additional layer of security against common web vulnerabilities.
Essential Security Headers
- Strict-Transport-Security (HSTS): Forces HTTPS connections Forces HTTPS connections
- Content-Security-Policy (CSP): Prevents XSS and injection attacks Prevents XSS and injection attacks
- X-Frame-Options: Protects against clickjacking Protects against clickjacking
- X-Content-Type-Options: Prevents MIME sniffing Prevents MIME sniffing
- Referrer-Policy: Controla la información de referencia Controls referrer information
- Permissions-Policy: Restringe las características del navegador Restricts browser features
Entendiendo nuestra Puntuación de Seguridad
Calificamos tus cabeceras de A+ a F basándonos en la presencia y configuración de cabeceras de seguridad críticas. Una calificación de A+ significa que todas las cabeceras recomendadas están configuradas correctamente.