HTTP headers are small pieces of information sent with every page. Security headers tell the visitor's browser how to behave, for example refusing to load your site inside another site's frame or only ever connecting over HTTPS. They help protect against clickjacking, cross-site scripting (XSS) and similar attacks.
StackCP lets you set these headers at the CDN, without editing code.
Where to find it
- Log in to your FimuroHost client area, go to Services, select your hosting plan and click Login to Control Panel / StackCP.
- In the CDN section, click Security Headers.
- Choose a value for each header you want to use and save.
The headers explained
Strict-Transport-Security (HSTS)
Tells browsers to use HTTPS only for your site. Set max-age in seconds (for example 31536000 for one year) and optionally includeSubDomains to apply it to every subdomain.
Tip: only enable includeSubDomains if every subdomain has a working SSL certificate. Start with a short max-age while testing.
X-Frame-Options
Controls whether other sites can show your pages in a frame, a common clickjacking trick.
DENY: never allow framing.SAMEORIGIN: allow framing only by pages on your own site (the usual choice for WordPress).
X-Content-Type-Options
The only value is nosniff. It stops browsers guessing a file's type, for example refusing a stylesheet that is not served as text/css. It is safe to turn on for almost every site.
Referrer-Policy
Controls how much of the previous page's address is shared when a visitor clicks a link. Options range from no-referrer (share nothing) to unsafe-url (share the full address, even from HTTPS to HTTP). The default, strict-origin-when-cross-origin, is a good balance and what most sites should keep.
X-XSS-Protection
An older header for the XSS filter built into some browsers. Values are 0 (off), 1 (sanitise the page), 1; mode=block (block the page) and 1; report= (report attacks). Modern browsers have removed this filter, so in 2026 it offers little protection; rely on Content-Security-Policy instead and use 0 or leave it unset if it causes problems.
Content-Security-Policy (CSP)
The most powerful header. It lists exactly which sources the browser may load scripts, styles, images, fonts and frames from, which blocks most injected code. It is also the easiest to get wrong, so build it gradually. Mozilla's MDN documentation lists every directive.
default-src 'self'; img-src 'self' data: https:; frame-ancestors 'self'
Testing your headers
- Purge the CDN cache after saving, then check your site with a free header scanner such as securityheaders.com.
- Open your browser's developer tools (Network tab) to see the headers on each response.
- If something breaks, such as missing fonts, embedded videos or payment widgets, loosen the relevant CSP rule rather than turning everything off.
Need help?
If anything here does not work as described, our team is happy to take a look. Open a support ticket from your FimuroHost client area or message us on WhatsApp at 01818160926.
Categories
Written by
FimuroHost Team
Technical Writer