Security (21 articles)

Mixed content

Mixed Content: How to Find and Fix HTTP Resources on HTTPS

Mixed content happens when an HTTPS page pulls in resources over plain HTTP. Browsers block the…
Learn More
X-frame-options header missing or invalid: how to fix it

X-Frame-Options Header Missing or Invalid: How to Fix It

Send a valid X-Frame-Options header (use SAMEORIGIN, or DENY if your pages are never framed) and…
Learn More
Password on http

Password on HTTP

Best practices guide for Password on HTTP (SE-014). Priority: Critical. Batch check required.
Learn More
Strict-transport-security (hsts) header missing: how to fix it

Strict-Transport-Security (HSTS) Header Missing: How to Fix It

Add a Strict-Transport-Security response header to force every browser onto HTTPS, starting with a short max-age,…
Learn More
Http url contains password input

Password Input on an HTTP Page: How to Fix This Now

A password field on a plain HTTP page means login details can be read off the…
Learn More
Content-security-policy header missing: how to add it

Content-Security-Policy Header Missing: How to Add It

The Content-Security-Policy (CSP) HTTP response header tells browsers which sources of scripts, styles, and other content…
Learn More

Get new blog posts by email: