add https security headers and remove malware from your website
Actions
About this gig
- Strict-Transport-Security
- Content-Security-Policy
- X-Frame-Options
- X-Content-Type-Options
- Referrer-Policy
- Permissions-Policy
Check your website at https://securityheaders.com; getting a lower grade (like B, C, D, F or even A) means you are not fully protected!
After this gig, you will get an A+ score (best score) at https://securityheaders.com indicating that everything has been done correctly.
To test your website, check the intro video
What credentials do I require?
- WordPress login (wp-admin)
- cPanel (in some cases)
What is a security header?
HTTP security headers are a fundamental part of website security. Upon implementation, they protect you against the types of attacks that your site is most likely to come across. These headers protect against XSS, code injection, clickjacking, etc.
Why HTTP Security Headers are necessary ?
Nowadays too many data breaches are happening, many websites are hacked due to misconfiguration or lack of protection. These security headers will protect your website from some common attacks like XSS, code injection, clickjacking, etc.
What is the purpose of HTTP headers?
The HTTP headers are used to pass additional information between the clients and the server through the request and response header. All the headers are case-insensitive, header fields are separated by colon, key-value pairs in clear-text string format.
You may also like the following gigs












