Mixed Content (HTTP Resources on HTTPS): How to Fix It

X-frame-options header missing or invalid: how to fix it

X-Frame-Options Header Missing or Invalid: How to Fix It

Send a valid X-Frame-Options header (use SAMEORIGIN, or DENY if your pages are never framed) and…
Learn More
Strict-transport-security (hsts) header missing: how to fix it

Strict-Transport-Security (HSTS) Header Missing: How to Fix It

Add a Strict-Transport-Security response header to force every browser onto HTTPS, starting with a short max-age,…
Learn More
Http url contains password input

Password Input on an HTTP Page: How to Fix This Now

A password field on a plain HTTP page means login details can be read off the…
Learn More
Content-security-policy header missing: how to add it

Content-Security-Policy Header Missing: How to Add It

The Content-Security-Policy (CSP) HTTP response header tells browsers which sources of scripts, styles, and other content…
Learn More
Mixed content - http resources on https

Mixed Content (HTTP Resources on HTTPS): How to Fix It

Mixed content happens when an HTTPS page loads sub-resources over plain HTTP, so fix it by…
Learn More
X-content-type-options header missing: how to fix it

X-Content-Type-Options Header Missing: How to Fix It

Add a single response header, X-Content-Type-Options: nosniff, so browsers trust your declared MIME types instead of…
Learn More

Get new blog posts by email: