HDR-001INJECTED
Content-Security-Policy
Content-Security-Policy: default-src 'self'CSP header is automatically added to prevent XSS attacks.
10 tests verify automatic injection of security headers.
Content-Security-Policy: default-src 'self'CSP header is automatically added to prevent XSS attacks.
Strict-Transport-Security: max-age=31536000; includeSubDomainsHSTS header enforces HTTPS connections.
Prevents clickjacking by controlling iframe embedding.
Prevents MIME type sniffing attacks.