What Are HTTP Security Headers?
HTTP security headers are directives sent by web servers that instruct browsers how to handle content. They provide an additional layer of security against common web vulnerabilities.
Essential Security Headers
- Strict-Transport-Security (HSTS): Forces HTTPS connections Forces HTTPS connections
- Content-Security-Policy (CSP): Prevents XSS and injection attacks Prevents XSS and injection attacks
- X-Frame-Options: Protects against clickjacking Protects against clickjacking
- X-Content-Type-Options: Prevents MIME sniffing Prevents MIME sniffing
- Referrer-Policy: Controla a informação de referência Controls referrer information
- Permissions-Policy: Restringe as funcionalidades do navegador Restricts browser features
Compreender a Nossa Pontuação de Segurança
Classificamos os seus cabeçalhos de A+ a F com base na presença e configuração de cabeçalhos de segurança críticos. Uma nota A+ significa que todos os cabeçalhos recomendados estão configurados corretamente.