Injection & XSS
X-Content-Type-Options
Stop MIME-sniffing.
What it is
With the value 'nosniff', the browser trusts the declared Content-Type instead of guessing it from the bytes.
Why it matters
Prevents a file you serve as text/data from being reinterpreted and executed as script or a stylesheet.
Risk without it
Without it, an uploaded 'image' or JSON endpoint can be coerced into executing as JavaScript in some browsers.
Recommended
nosniff
Set it
add_header X-Content-Type-Options "nosniff" always;