Webserver secure config
Apache2
Header set X-Content-Type-Options nosniff
Header always set Strict-Transport-Security "max-age=63072000; includeSubdomains; preload"
Header always set X-XSS-Protection "1; mode=block"
Header set X-Frame-Options: "SAMEORIGIN"