XSS Protection
What Barrion checks when it evaluates your site's protection against script injection attacks.
Barrion checks for protections against cross-site scripting (XSS), attacks where malicious scripts are injected into your pages and executed in visitors' browsers. These scripts can steal login sessions, redirect users to phishing sites, or perform actions on a victim's behalf.
What Barrion Checks
X-XSS-Protection (Deprecated)
Barrion checks for the presence of this legacy header, which was once used by older browsers as an XSS filter. This header is now deprecated and in some configurations can actually introduce vulnerabilities rather than prevent them. It should be removed from your responses.
Severity: Low
Anti-CSRF Tokens
Barrion checks whether your site uses protection against Cross-Site Request Forgery (CSRF), attacks where a malicious website tricks an authenticated user into unknowingly submitting a form or triggering an action on your site.
Severity: Medium
Vulnerable JavaScript Libraries
Barrion detects third-party JavaScript libraries loaded by your page that have known security vulnerabilities. Outdated libraries are one of the most common ways vulnerabilities enter otherwise well-built applications.
Severity: High
Mixed Content
Barrion checks whether your HTTPS site loads any resources (scripts, images, fonts, iframes) over an unencrypted HTTP connection. Resources loaded over HTTP on a secure page can be intercepted and replaced by an attacker.
Severity: High
What to Do
Share High severity findings with your development team as a priority. Vulnerable library findings include the library name and version detected, making it straightforward to identify what needs updating. Mixed content findings list the specific resources loaded insecurely. Lower severity findings like the deprecated XSS header are quick wins, typically a one-line removal from your server configuration.