X-XSS-Protection
X-XSS-Protection enabled a built-in reflected-XSS filter in older browsers. That filter is now removed from modern browsers and, in the past, its behaviour actually created new vulnerabilities. Current best practice is to disable it with a value of 0 and rely on a strong Content Security Policy instead.
Why it matters
Legacy XSS filter for older browsers. Modern browsers use CSP instead. Set to "0" to avoid false positives.
How to add X-XSS-Protection
add_header X-XSS-Protection "0" always;Recommended value
0Avoid
1; mode=block (legacy filter — can be abused)Frequently asked questions
Why set X-XSS-Protection to 0 instead of removing it?
Explicitly sending 0 guarantees the legacy filter is off in any browser that still honours the header, avoiding filter-based side channels. A strong CSP is the real defense against XSS.
Will 0 make my site less secure?
No. Modern browsers no longer ship the XSS Auditor, and where it did exist it caused more problems than it solved. Content Security Policy replaces it.
Related reading
Other header guides
What the HSTS header does, how to configure max-age, includeSubDomains and preload, and how to add it in Nginx, Apache, and Cloudflare.
Why the X-Content-Type-Options: nosniff header matters, what MIME sniffing is, and how to set it in Nginx, Apache, and Cloudflare.
How X-Frame-Options prevents clickjacking, DENY vs SAMEORIGIN, why frame-ancestors supersedes it, and how to set it in Nginx, Apache, and Cloudflare.
How Referrer-Policy limits the referrer data sent to other sites, the safest values, and how to configure it in Nginx, Apache, and Cloudflare.
Is X-XSS-Protection set on your site?
Scan any URL free to check X-XSS-Protection and every other security header.
Scan Now - Free