Barrion Docs
Passive Scanning

Security Headers

What Barrion checks when it evaluates your site's HTTP security headers.

Barrion checks whether your server includes HTTP headers that instruct the browser to enable built-in security features. These headers are among the easiest security improvements to make. A few lines of configuration can prevent entire categories of attack.

What Barrion Checks

HSTS (HTTP Strict Transport Security)

Barrion checks whether your site sends the HSTS header, which tells browsers to always connect over HTTPS and never use an unencrypted connection, even if a user types http:// in the address bar.

Without HSTS, there is a brief window when a visitor first arrives where an attacker on the same network could intercept the connection before the redirect to HTTPS occurs.

Severity: High

X-Content-Type-Options

Barrion checks for this header, which prevents browsers from guessing the type of content in a response. Without it, a browser might treat an uploaded file as executable code, even if it was not intended to be.

Severity: Medium

Referrer-Policy

Barrion checks whether your site controls how much information is shared when visitors navigate from your pages to other websites. Without this header, the full URL of the page they came from, including any query parameters, may be sent to the destination site.

Severity: Medium

Permissions-Policy

Barrion checks whether your site restricts access to sensitive browser features such as the camera, microphone, and geolocation. Without this header, any script or embedded content on your page could potentially request access to these features.

Severity: Medium

Server Information Disclosure

Barrion checks whether your server reveals its software name and version in response headers. This information can help attackers identify known vulnerabilities in specific versions of server software.

Severity: Low

Content-Type

Barrion checks whether your responses include accurate content type declarations. Missing or incorrect content types can cause browsers to misinterpret response content.

Severity: Medium

What to Do

Security headers are added at the server or reverse proxy level and apply to all responses automatically. Share findings with your developer or hosting provider. Most of these are single-line configuration changes. If you use Barrion's AI recommendations, it can generate the specific configuration for your server.