Low severity Vulnerability

Missing Security Headers

Absent CSP, HSTS, X-Frame-Options and Referrer-Policy leave the browser with no guard rails.

Overview

Security headers are cheap defence in depth. Without a Content-Security-Policy an XSS bug becomes full account takeover; without X-Frame-Options or frame-ancestors the page is clickjackable; without HSTS a first visit can be downgraded.\nEach header closes a whole class of client-side attacks rather than a single bug.

Indicators of Compromise

Signals that suggest this is present on a system.

  • No Content-Security-Policy response header
  • Missing Strict-Transport-Security
  • Page renderable inside an iframe

Controls that stop it

  • Harden TLS and Security Headers

    Serve everything over TLS with HSTS so downgrades are impossible, set a modern Content-Security-Policy, enable HSTS preload, deny framing with frame-ancestors, and switch on Referrer-Policy and Permissions-Policy. Disable unused legacy protocols and cipher suites rather than leaving them configured for compatibility.

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used