headers by 0x6a03448f4d
← All headers
Injection & XSS

X-Content-Type-Options

Stop MIME-sniffing.

What it is

With the value 'nosniff', the browser trusts the declared Content-Type instead of guessing it from the bytes.

Why it matters

Prevents a file you serve as text/data from being reinterpreted and executed as script or a stylesheet.

Risk without it

Without it, an uploaded 'image' or JSON endpoint can be coerced into executing as JavaScript in some browsers.

Recommended

nosniff

Set it

add_header X-Content-Type-Options "nosniff" always;

References