[Resolved] Security header for XSS Protection

Home Forums Support [Resolved] Security header for XSS Protection

Home Forums Support Security header for XSS Protection

Viewing 4 posts - 1 through 4 (of 4 total)
  • Author
    Posts
  • #721861
    Gunter Tannhaeuser

    Hello,

    we chekced our website with an external Serivce, theyre report tellus some “problems” …

    Missing security header for XSS Protection on https://XXXXXXX.xx/wp-content/themes/generatepress/.

    Missing security header to prevent Content Type sniffing on https://XXXXXXX.xx/wp-content/themes/generatepress/.

    Missing Strict-Transport-Security security header on https://XXXXXXX.xx/wp-content/themes/generatepress/.

    I am not a professional WP-Nerd, so i feel a little bit unsafe about this

    #722347
    David
    Staff
    Customer Support

    Hi there,

    i can’t see these errors on the site. What external service was it you used?

    #722728
    Gunter Tannhaeuser

    Hello,

    this was funny , i cant find the service again. I learned: Stealth mode in my browser has a dark side ๐Ÿ˜

    Perhabs they only want to frighten us to sell a service? Whatever, if you say you cant find it i am happy ๐Ÿ™‚

    Thank you very much!

    #722939
    David
    Staff
    Customer Support

    So if you want to check, you can open the Audit tool in Chrome (Right Click > Inspect and open the Audit in the console, may be hidden in the 3 dot menu). Run that and it will show issues under best practices. Some of the errors are just warnings a lot of which are false positives.

    But i can’t see the XSS issues raised. Let me know if anything comes up.

Viewing 4 posts - 1 through 4 (of 4 total)
  • You must be logged in to reply to this topic.