🚫
Security

XSS attacks: Cross-Site Scripting protection

10.02.2025
← All articles

XSS — executing foreign JavaScript on your site. Cookie theft, session hijack.

Types

Reflected, Stored, DOM-based.

Protection: escaping

htmlspecialchars($input, ENT_QUOTES, 'UTF-8').

CSP

Content-Security-Policy header — blocks external scripts.

HttpOnly cookies

JS can't read cookies.

Framework auto-escape

React, Vue, Angular.

Related articles

🔐 Password managers — choosing between Bitwarden, 1Password, LastPass and KeePass 🍯 Honeypot — hidden form field that catches bots and stops spam 📄 /.well-known/security.txt — security contact standard 📋 GDPR Compliance — obligations for protecting European citizens' data
🌐 Language
🇺🇿 O'zbek 🇺🇿 Ўзбек 🇷🇺 Русский 🇬🇧 English ✓