Security Headers
What Barrion checks when it evaluates your site's HTTP security headers.
Barrion checks whether your server includes HTTP headers that instruct the browser to enable built-in security features. These headers are among the easiest security improvements to make. A few lines of configuration can prevent entire categories of attack.
What Barrion Checks
HSTS (HTTP Strict Transport Security)
Barrion checks whether your site sends the HSTS header, which tells browsers to always connect over HTTPS and never use an unencrypted connection, even if a user types http:// in the address bar.
Without HSTS, there is a brief window when a visitor first arrives where an attacker on the same network could intercept the connection before the redirect to HTTPS occurs.
Severity: High
X-Content-Type-Options
Barrion checks for this header, which prevents browsers from guessing the type of content in a response. Without it, a browser might treat an uploaded file as executable code, even if it was not intended to be.
Severity: Medium
Referrer-Policy
Barrion checks whether your site controls how much information is shared when visitors navigate from your pages to other websites. Without this header, the full URL of the page they came from, including any query parameters, may be sent to the destination site.
Severity: Medium
Permissions-Policy
Barrion checks whether your site restricts access to sensitive browser features such as the camera, microphone, and geolocation. Without this header, any script or embedded content on your page could potentially request access to these features.
Severity: Medium
Server Information Disclosure
Barrion checks whether your server reveals its software name and version in response headers. This information can help attackers identify known vulnerabilities in specific versions of server software.
Severity: Low
Content-Type
Barrion checks whether your responses include accurate content type declarations. Missing or incorrect content types can cause browsers to misinterpret response content.
Severity: Medium
What to Do
Security headers are added at the server or reverse proxy level and apply to all responses automatically. Share findings with your developer or hosting provider. Most of these are single-line configuration changes. If you use Barrion's AI recommendations, it can generate the specific configuration for your server.