What is Content-Security-Policy (CSP)?
A powerful HTTP defense header enforcing explicit whitelists of trusted script, frame, and asset sources to block Cross-Site Scripting (XSS) vectors.
Micro-Technology Solutions
Inspect live HTTP response headers, detect technology leaks, and audit HSTS, CSP, and Permissions-Policy.
Defense-in-depth against XSS, Clickjacking, MIME sniffing, and information disclosure.
CSP establishes strict whitelists of trusted domains for scripts, styles, and assets, acting as the primary defense against Cross-Site Scripting (XSS).
HSTS forces browsers to strictly use HTTPS encrypted connections, preventing SSL-stripping and MITM downgrade attacks.
Prevents invisible iframe embedding on third-party sites using `X-Frame-Options: SAMEORIGIN` or CSP `frame-ancestors 'self'`.
Directives like `Cache-Control: private` safeguard user data while hiding `Server` and `X-Powered-By` denies automated vulnerability fingerprinting.
Step-by-step fixes for CORS errors, CSP blocking, HSTS lockouts, and aggressive caching.
The 'Referer' misspelling legacy, HTTP 418 Teapot, and the Terry Pratchett Clacks header.
In 1996, authors of RFC 1945 accidentally misspelled 'Referrer' as 'Referer'. Correcting it would break existing web systems, cementing the typo forever.
Published in RFC 2324 as an April Fools joke for hyper text coffee pots, HTTP 418 refuses to brew coffee because it's a teapot. Many servers still implement it as an easter egg.
Thousands of servers send `X-Clacks-Overhead: GNU Terry Pratchett`. In Discworld lore, a person's name never dies as long as it's echoed across the transmission lines.
Default server headers advertise software and OS versions. Suppressing them stops 90% of automated port-scanning bots looking for version-targeted exploits.
Learn the fundamental concepts, protocols, and technical terminology of this tool.
A powerful HTTP defense header enforcing explicit whitelists of trusted script, frame, and asset sources to block Cross-Site Scripting (XSS) vectors.
Commands user-agents whether a web page may be rendered inside `<iframe>` tags, mitigating deceptive UI redressing attacks (Clickjacking).
A browser security mechanism utilizing HTTP headers to grant or deny web applications access to resources hosted across distinct origin domains.
Governs the quantity of originating URL path information attached in the `Referer` request header when clients navigate to external destinations.