Fix guides

Vulnerability fix guides, with platform-specific examples.

Step-by-step guides to fix common web security findings. Each guide explains what the issue is, why it matters, and how to fix it, with examples for Nginx, Apache, Node, and more.

Security Headers

How to fix a missing HSTS header

Enable HTTP Strict Transport Security (HSTS) step by step to stop downgrade attacks and force HTTPS. Nginx, Apache, Node and Next.js.
Security Headers

Fix missing or weak Content Security Policy (CSP)

Set up a Content Security Policy (CSP) step by step to prevent XSS and injection, with safe defaults for Nginx, Apache and frameworks.
TLS / HTTPS

How to fix mixed content (HTTP on HTTPS pages)

Fix mixed content errors: resources loaded over HTTP on an HTTPS page. Step-by-step guide to find and fix scripts, images, and iframes.
Cookie Security

Fix insecure cookies (Secure, HttpOnly, SameSite)

Add Secure, HttpOnly and SameSite to your cookies to prevent theft and cross-site attacks. Set-Cookie examples for Node, Rails and servers.
Security Headers

Fix clickjacking: X-Frame-Options, frame-ancestors

Prevent clickjacking with X-Frame-Options or CSP frame-ancestors so no other site can frame yours. Nginx, Apache and framework examples.
TLS / HTTPS

How to fix SSL/TLS certificate expiry

Prevent certificate expiry: renew and install SSL/TLS certificates before they expire. Automation with Let's Encrypt and monitoring tips.
Security Headers

How to add Referrer-Policy header

Set a Referrer-Policy header to control how much referrer data leaves your site and reduce leakage. Nginx, Apache and framework examples.
Security Headers

How to add X-Content-Type-Options header

Prevent MIME sniffing: set X-Content-Type-Options: nosniff so browsers use the declared Content-Type. Nginx, Apache, and framework examples.
Security Headers

How to add Permissions-Policy header

Restrict camera, mic, geolocation and other browser features with Permissions-Policy. Step by step, with Nginx, Apache and Node examples.
Information Disclosure

Fix server info disclosure (Server, X-Powered-By)

Stop leaking server and platform details in HTTP headers. Remove or genericize Server and X-Powered-By on Nginx, Apache, Node and PHP.
TLS / HTTPS

Fix weak TLS (disable 1.0, 1.1, weak ciphers)

Harden TLS: disable TLS 1.0 and 1.1, drop weak ciphers, prefer TLS 1.3. Step-by-step for Nginx, Apache, and load balancers. Test with Barrion.
Email Security

How to fix missing or weak SPF, DKIM, and DMARC

Set up SPF, DKIM, and DMARC for your domain to stop email spoofing and improve deliverability. Step-by-step with DNS and policy examples.
Security Headers

How to fix an overly permissive CORS policy

Tighten CORS: avoid Access-Control-Allow-Origin *. Set specific origins, check credentials. Step-by-step for Nginx, Node, and API gateways.
TLS / HTTPS

How to add CAA DNS records (allowlist trusted CAs)

Allowlist the certificate authorities that can issue for your domain. Step-by-step CAA DNS record setup to prevent mis-issuance and rogue certs.
TLS / HTTPS

How to enable OCSP stapling for faster TLS

Enable OCSP stapling so clients verify cert revocation in the TLS handshake. Faster connections, better privacy, no extra round-trip to the CA.
DNS Security

How to fix subdomain takeover risk

Find and fix dangling DNS records that point at deprovisioned cloud resources: inventory, remove, reclaim and monitor your subdomains.
Supply Chain

How to fix vulnerable JavaScript libraries

Find and remove vulnerable JavaScript dependencies with npm audit and yarn audit. Upgrade, replace abandoned libraries and gate in CI.
Network Security

How to fix exposed open ports with firewall rules

Lock down public-facing ports with host firewalls and cloud security groups. Inventory listening services, narrow access to allowlisted CIDRs.

Every guide here fixes a configuration issue, the kind a passive scan finds. The flaws that do the most damage, like broken access control, IDOR and injection, only show up when someone tests the app the way an attacker would. That's what an AI pentest does, and it can rerun continuously on a schedule. Findings are checked against your live app before they're reported. Here's how continuous pentesting works.

Check your site for these findings.

Run a free passive scan to see which of these apply to your web app, with a fix for each. A scan finds configuration issues like these. A pentest finds the ones that can be exploited.

A scan shows the surface. A pentest tests what gets in.

Passive scan

  • Reads what your app already exposes
  • Never logs in or submits a form
  • Cannot confirm what is exploitable

Active AI pentest

  • Tests your app the way an attacker would
  • Chains requests to confirm real exploits
  • Replays findings against your live app
  • Runs on a schedule or on demand, retests free

Probes for

  • SQL injection
  • Broken access control
  • IDOR
  • SSRF
  • Business-logic abuse

How AI pentesting works

Paid in credits. Free retests of found issues, and expert review from Standard up.