Vulnerability fix guides, with platform-specific examples.
Step-by-step guides to fix common web security findings. Each guide explains what the issue is, why it matters, and how to fix it, with examples for Nginx, Apache, Node, and more.
How to fix a missing HSTS header
Fix missing or weak Content Security Policy (CSP)
How to fix mixed content (HTTP on HTTPS pages)
Fix insecure cookies (Secure, HttpOnly, SameSite)
Fix clickjacking: X-Frame-Options, frame-ancestors
How to fix SSL/TLS certificate expiry
How to add Referrer-Policy header
How to add X-Content-Type-Options header
How to add Permissions-Policy header
Fix server info disclosure (Server, X-Powered-By)
Fix weak TLS (disable 1.0, 1.1, weak ciphers)
How to fix missing or weak SPF, DKIM, and DMARC
How to fix an overly permissive CORS policy
How to add CAA DNS records (allowlist trusted CAs)
How to enable OCSP stapling for faster TLS
How to fix subdomain takeover risk
How to fix vulnerable JavaScript libraries
How to fix exposed open ports with firewall rules
Every guide here fixes a configuration issue, the kind a passive scan finds. The flaws that do the most damage, like broken access control, IDOR and injection, only show up when someone tests the app the way an attacker would. That's what an AI pentest does, and it can rerun continuously on a schedule. Findings are checked against your live app before they're reported. Here's how continuous pentesting works.
Check your site for these findings.
Run a free passive scan to see which of these apply to your web app, with a fix for each. A scan finds configuration issues like these. A pentest finds the ones that can be exploited.