VibeCoded

Do security headers matter for my app?

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

They matter a little. Security headers such as Content-Security-Policy, Strict-Transport-Security and X-Content-Type-Options tell browsers to block some attacks, and most hosting platforms let you add them in minutes. Scanners report missing headers prominently, but they are rarely the serious finding. Fix them, then spend your attention on authorization and database rules.

The useful ones

Headers worth setting
HeaderWhat it does
Strict-Transport-SecurityForces HTTPS on return visits
Content-Security-PolicyLimits where scripts can load from, reducing XSS impact
X-Content-Type-Options: nosniffStops browsers guessing file types
Referrer-PolicyControls what URL is sent to other sites
frame-ancestors (in CSP)Stops your app being framed for clickjacking

Adding them

Set them in your host's configuration (for example a headers file or the platform's settings) or at a CDN such as Cloudflare. Start Content-Security-Policy in report-only mode so it does not break your app.

Checking yours

Open your site, then the browser's developer tools, and look at the response headers on the main page. Free online header checkers grade them in seconds. Typical AI-built apps hosted on modern platforms already have HTTPS and some defaults; most are missing a Content-Security-Policy and sometimes Strict-Transport-Security.

Add HSTS once you are sure the whole site, including subdomains you include, works over HTTPS. Build the Content-Security-Policy gradually: start with report-only, list the domains your app actually loads scripts and styles from, and tighten from there. A strict policy is one of the best defences against XSS, because it stops injected scripts from running even when a sanitising step is missed. Then move on: headers are hygiene, and the findings that cause breaches are elsewhere.

Getting it checked

TrazTech offers vibe-coding QA and security review, listed from $2,000 CAD. Get at least one other quote on the same scope; the questions to ask a testing firm help compare them.

Get a scope for your app

Tell us what you built, what it stores and who is about to use it.

Get matched

Common questions

Why does my scanner rate these as high?

Scanners score what they can see. A tester scores what an attacker can do, and missing headers alone rarely let them do much.

Will a strict CSP break my AI-built app?

It can, if the app loads scripts from many places. Test in report-only mode first.