Skip to content
This repository was archived by the owner on Apr 16, 2026. It is now read-only.
This repository was archived by the owner on Apr 16, 2026. It is now read-only.

Modification of X-XSS Protection best practice configuration #87

@g-noth

Description

@g-noth

According to OWASP Secure Headers Project the X-XSS header should be set as X-XSS-Protection: 0 and therefore should not be penalized by the scoring methodology. A counterproposal would be to give more weight to CSP.

Source:
https://owasp.org/www-project-secure-headers/#x-xss-protection

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions