Security headers tell browsers to apply extra protections to your site.
A safe starting set
<IfModule mod_headers.c>
Header always set X-Content-Type-Options "nosniff"
Header always set Referrer-Policy "strict-origin-when-cross-origin"
Header always set X-Frame-Options "SAMEORIGIN"
Header always set Permissions-Policy "camera=(), microphone=(), geolocation=()"
</IfModule>
| Header | Protects against |
|---|---|
X-Content-Type-Options | Browsers guessing a file is executable |
Referrer-Policy | Leaking full URLs to other sites |
X-Frame-Options | Your pages being framed by other sites (clickjacking) |
Permissions-Policy | Pages using browser features they don’t need |
These rarely break anything. If your site embeds itself in frames on another domain, or uses the camera or location, adjust accordingly.
HSTS
Once HTTPS works for the domain and every subdomain you use:
Header always set Strict-Transport-Security "max-age=31536000"
Browsers then refuse plain HTTP for a year. Don’t add includeSubDomains or preload unless every subdomain has working HTTPS.
Content-Security-Policy
CSP is the most powerful header and the easiest to get wrong. Start in report-only mode:
Header always set Content-Security-Policy-Report-Only "default-src 'self'; img-src 'self' data: https:"
Check the browser console for what would be blocked, adjust, then switch to Content-Security-Policy.
Checking
Open developer tools → Network, select the page request and view Response Headers, or use an online security headers checker.
New to Traxio? The PHP hosting page lists the PHP versions, database and tools every account gets, free for the first 30 days.