⚙️
PHP Tools Hub
Tools
PHP
Quick
Contact
Home
>
Tutorials
>
HTML
>
HTML Security
HTML Security Tutorials
54 tutorials found.
📘
Allow Specific Inline Script
CSP Hash | Script Hash | HTML
📘
Allowed Extensions
File Upload Security | Validate File Type | HTML
📘
Automatic Trust Propagation
CSP Strict Dynamic | Trusted Scripts | HTML
📘
Client and Server Side
Form Security | Input Validation | HTML
📘
Control Resource Loading
Content Security Policy | CSP Header | HTML
📘
DENY or SAMEORIGIN
Clickjacking Prevention | X-Frame-Options | HTML
📘
Escape User Input
XSS Prevention | Cross Site Scripting | HTML
📘
Feature Control
Permission Policy | Permissions-Policy | HTML
📘
Feature Policy Header
Permissions Policy | Permissions-Policy | HTML
📘
Inline Script Allow
CSP Nonce | Random Nonce | HTML
📘
Parameterized Queries
SQL Injection Prevention | Use Prepared Statements | HTML
📘
Partitioned Cookies
CHIPS | Cookies Having Independent Partitioned State | HTML
📘
Prevent DOM XSS
Trusted Types | Trusted Types API | HTML
📘
Protect Sensitive Data
CORB | Cross Origin Read Blocking | HTML
📘
Restrict Iframe Capabilities
Iframe Security | Sandbox Attribute | HTML
📘
Same Origin
CORP | Cross Origin Resource Policy | HTML
📘
Shared Memory Access
Cross Origin Isolation | COOP COEP | HTML
📘
Use Anti CSRF Tokens
CSRF Prevention | Cross Site Request Forgery | HTML
📘
Use HTTPS Forms
Sensitive Data | No Passwords in HTML | HTML
📘
Avoid Direct SQL Concatenation
SQL Injection Prevention | Escape Input | HTML
📘
Avoid innerHTML
XSS Prevention | Sanitize HTML | HTML
📘
Create Trusted Policy
Trusted Types | Policy Creation | HTML
📘
Disable Location Access
Permission Policy | Geolocation | HTML
📘
Enable Disable Features
Permissions Policy | Feature Control | HTML
📘
Encrypt Form Submission
Form Security | HTTPS Only | HTML
📘
Explicit Permissions
Iframe Security | Allow Attribute | HTML
📘
Fallback Directive
Content Security Policy | default-src | HTML
📘
Partitioned Cookie Flag
CHIPS | Partitioned Attribute | HTML
📘
Restrict Framing
Clickjacking Prevention | CSP frame-ancestors | HTML
📘
Same Origin Allow Popups
Cross Origin Isolation | Cross Origin Opener Policy | HTML
📘
SameSite=Lax or Strict
CSRF Prevention | SameSite Cookies | HTML
📘
Server Side Scanning
File Upload Security | Scan for Malware | HTML
📘
Use Environment Variables
Sensitive Data | No API Keys in Frontend | HTML
📘
Allowed Script Sources
Content Security Policy | script-src | HTML
📘
Alternative to Third Party Cookies
CHIPS | Third Party Cookies | HTML
📘
Include in Forms
Form Security | CSRF Tokens | HTML
📘
Instead of innerHTML
XSS Prevention | Use textContent | HTML
📘
Media Device Control
Permission Policy | Camera Microphone | HTML
📘
Prevent Direct Access
File Upload Security | Store Outside Web Root | HTML
📘
Require CORP
Cross Origin Isolation | Cross Origin Embedder Policy | HTML
📘
Require Trusted Types
Trusted Types | Enforcement | HTML
📘
Send Only Required Data
Sensitive Data | Minimize Data Exposure | HTML
📘
Allowed Style Sources
Content Security Policy | style-src | HTML
📘
Content Security Policy
XSS Prevention | CSP Header | HTML
📘
COOP Header
Cross Origin Isolation | Cross Origin Opener Policy | HTML
📘
Prevent Brute Force
Form Security | Rate Limiting | HTML
📘
Allowed Image Sources
Content Security Policy | img-src | HTML
📘
COEP Header
Cross Origin Isolation | Cross Origin Embedder Policy | HTML
📘
Prevent JavaScript Access
XSS Prevention | HTTP Only Cookies | HTML
📘
API Endpoints
Content Security Policy | connect-src | HTML
📘
CORP Header
Cross Origin Isolation | Cross Origin Resource Policy | HTML
📘
Prevent Clickjacking
Content Security Policy | frame-ancestors | HTML
📘
SharedArrayBuffer
Cross Origin Isolation | Shared Memory Access | HTML
📘
Report Violations
Content Security Policy | report-uri | HTML