Some of the web's most effective defenses aren't code — they're a handful of HTTP response headers that tell browsers "don't fall for this." They cost almost nothing to deploy and neutralize entire attack classes. Here's what each one does.
The essential five
- Strict-Transport-Security (HSTS) — forces HTTPS for future visits, defeating SSL-stripping attacks.
max-age=31536000; includeSubDomainsis the standard starting point. - Content-Security-Policy (CSP) — the heavyweight. It whitelists where scripts, styles, images, and frames may load from, so an injected
<script>from an attacker's domain simply doesn't execute. It's the single best XSS mitigation available. - X-Frame-Options / frame-ancestors — controls who may embed your page in a frame, blocking clickjacking. Modern setups use CSP's
frame-ancestorsdirective; the standalone header remains as a fallback. - X-Content-Type-Options: nosniff — stops browsers from "sniffing" content types, which prevents attacks that smuggle scripts inside innocent-looking files.
- Referrer-Policy — limits what the browser reveals in the
Refererheader.strict-origin-when-cross-originkeeps full URLs internal while sending only the origin to third parties.
Worth adding next
Permissions-Policy disables powerful browser features (camera, geolocation, payment) your page doesn't need — shrinking what a successful XSS can reach for. Cross-Origin-Opener-Policy and Cross-Origin-Embedder-Policy isolate your page's process from other origins, which also unlocks high-resolution timers and SharedArrayBuffer for performance-sensitive apps.
Related reading: How to Remain Valuable When Intelligence Becomes Cheap — a 224-page practical book on staying valuable as intelligence gets cheap. $3.84. Read it on Gumroad →
How to check a site
Headers are public — any response carries them. The security headers checker fetches a URL and grades what's present and what's missing, and the HTTP header security analyser goes deeper into each header's directives. Run your own site first (you may be surprised), then make the fixes one header at a time — CSP especially deserves a report-only trial run before enforcement, since an over-strict policy breaks legitimate functionality.
Why this is cheap security
Headers are declarative: no dependencies, no runtime cost, no code paths to maintain. A few lines of server configuration buy protection that would take thousands of lines of application code to approximate. There's no better effort-to-safety ratio on the web.