Security headers
What are security headers?
Security headers are instructions a web server sends to the browser with every page, limiting what can happen to that page once it loads. They say, for example, to open the site over HTTPS only, which addresses may supply code, and whether another site may embed it. They do not fix vulnerabilities; they limit the damage. The two that matter most are CSP and HSTS, and online scanners grade them from A+ to F.
Example
A store owner runs their address through securityheaders.com and gets an F: the server’s response lacks the headers the scanner looks for. These are the ones usually added:
| Header | What it tells the browser |
|---|---|
| Strict-Transport-Security (HSTS) | open this site over HTTPS only; max-age=31536000 means one year (365 × 24 × 3,600 seconds) |
| Content-Security-Policy (CSP) | run code only from the site itself and the services listed, such as analytics, payments and chat |
| X-Frame-Options (or frame-ancestors in CSP) | do not show this page inside another site |
| X-Content-Type-Options | do not guess a file’s type; trust the declared one |
| Referrer-Policy | how much of the address to pass on to the next site |
| Permissions-Policy | which features, such as camera, microphone and location, the page may use |
Most of these are a few lines of server configuration. CSP takes longer: it runs first in report-only mode (Content-Security-Policy-Report-Only) to show what it would block, and is enforced only after that. HSTS goes on once the whole site works over HTTPS, because browsers remember the rule until it expires.
Why it matters for a business
Headers protect visitors when something else has already gone wrong. CSP decides which JavaScript may run on a page and where it may send data. If a foreign script gets into the site through an old plugin or a compromised third-party service, CSP can stop it loading, or stop it sending what customers type to someone else’s server. That matters most on login and checkout pages. HSTS stops a returning visitor’s connection being downgraded to plain HTTP, on public Wi-Fi for instance. A framing rule blocks clickjacking, the trick of loading your page invisibly over someone else’s, so a visitor clicks what they can see and hits yours instead.
The grade is also public. Anyone can scan your site, including a larger client vetting its suppliers. An A+ does not mean the site is secure; it means the instructions to the browser are in order.
What to ask
- Where are the headers set (the server, the CDN or the application), and who maintains them when things change?
- Is there a CSP, and does it block or only report? How many exceptions like
unsafe-inlinedoes it carry? - Does HSTS cover subdomains, and are all of them ready for HTTPS?
- Who updates the CSP when marketing adds a new script, such as a pixel, a chat widget or a map?
Headers are the quick check. Our website security test goes further: it tries the attacks themselves, cross-site scripting among them, and shows which weaknesses can actually be exploited.