מאגר ידע

Security headers and cookies

המאמר עדיין לא תורגם; הוא מוצג באנגלית.

Response headers tell browsers how to treat your site. Vigavo reads the headers of your homepage:

  • hsts_missing: no Strict-Transport-Security; browsers are not told to always use HTTPS.
  • csp_missing: no Content-Security-Policy; nothing limits which scripts may run. Setting one needs testing so it does not block your own code.
  • frame_missing: no X-Frame-Options or frame-ancestors; your page can be embedded in someone else's (clickjacking).
  • xcto_missing: no X-Content-Type-Options: nosniff.
  • referrer_missing: no Referrer-Policy; full page addresses leak to other sites.
  • permissions_policy_missing: no Permissions-Policy for camera, microphone, location and similar features.
  • cookie_flags (security): cookies without Secure, HttpOnly or SameSite.
  • server_version / powered_by: the server announces its software or exact version.

Most of these are set in one place: your host's or CDN's header settings, a next.config.js / vercel.json headers block, or the web server configuration. On hosted builders some headers are controlled by the platform: see Managed by your platform.

After changing headers, verify the fix with a new scan.

נבדק לאחרונה 7 באוק׳ 2026, 0:00:00

עדיין תקועים? שלחו פנייה

משוב
סוג