#Security headers
Security headers are short instructions a web server sends to the browser with every page. Articles tagged here explain headers such as Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy. Each guide describes what the header protects against in plain words. You will find ready-to-adapt examples for Apache, Nginx and common hosting setups. The articles also explain how to roll out a header safely without breaking the site. Read them when an audit reports missing or weak headers.
2026/10/01 · 8分で読めますCORS Explained: The Misconfigurations That Expose Your Data
CORS decides which other websites may read your responses. Learn how it works, the common misconfigurations that leak data, and how to set it…
2026/09/29 · 8分で読めますCSRF Explained: How Cross-Site Request Forgery Works
Cross-site request forgery tricks a logged-in browser into acting on your site. Learn how CSRF works, how tokens and SameSite cookies stop it and…
2026/09/28 · 8分で読めますX-Content-Type-Options: nosniff and Safe MIME Types Explained
X-Content-Type-Options: nosniff stops browsers from guessing file types, closing a path for disguised scripts. Learn how MIME sniffing works and how to set it.
2026/09/27 · 7分で読めますWebsite Security Audit Checklist: What to Check and in What Order
A practical website security audit checklist: HTTPS, certificates, headers, software, access, backups, DNS and e-mail, ordered by impact with clear targets.
2026/09/16 · 8分で読めますSubresource Integrity: Protect Your Site From Tampered Scripts
Subresource Integrity lets browsers reject third-party scripts and styles that have been changed. Learn how SRI works, when to use it and where it…
2026/09/15 · 8分で読めますHow to Add Security Headers on Apache, Nginx, WordPress and CDNs
Copy-ready examples for adding HSTS, CSP, X-Frame-Options and other security headers on Apache, Nginx, WordPress hosting and CDNs, plus how to verify them.
2026/09/08 · 8分で読めますPermissions-Policy Header: Control Camera, Location and More
Permissions-Policy lets you switch off browser features like camera, microphone and geolocation for your pages and embedded iframes. Here is how to set it.
2026/09/07 · 8分で読めますReferrer-Policy Header: Which Value to Use and Why It Matters
Referrer-Policy controls how much of your page URLs other sites see. Learn what each value does, the safe default, and how it affects analytics…
2026/09/04 · 8分で読めますHow to Get an A Grade in an SSL Server Test: A Practical Guide
A poor SSL test grade usually comes from old protocols, weak ciphers, chain issues or missing HSTS. Learn what the tests check and how…
2026/08/31 · 8分で読めますsecurity.txt: How to Add a Security Contact to Your Website
A security.txt file tells researchers how to report vulnerabilities on your site. Learn the required fields, where to place it and how to handle…
2026/08/19 · 8分で読めますWordPress Security Checklist: 20 Steps That Actually Matter
A practical WordPress security checklist for owners and agencies: updates, plugins, logins, backups, HTTPS, headers and monitoring, ordered by real impact.
2026/08/17 · 8分で読めますClickjacking Protection: X-Frame-Options vs frame-ancestors
Clickjacking tricks visitors into clicking hidden buttons on your site inside another page. Learn how X-Frame-Options and CSP frame-ancestors stop it.