X-XSS-Protection

X-XSS-Protection enabled a built-in reflected-XSS filter in older browsers. That filter is now removed from modern browsers and, in the past, its behaviour actually created new vulnerabilities. Current best practice is to disable it with a value of 0 and rely on a strong Content Security Policy instead.

Why it matters

Legacy XSS filter for older browsers. Modern browsers use CSP instead. Set to "0" to avoid false positives.

How to add X-XSS-Protection

add_header X-XSS-Protection "0" always;

Recommended value

0

Avoid

1; mode=block  (legacy filter — can be abused)

Frequently asked questions

Why set X-XSS-Protection to 0 instead of removing it?

Explicitly sending 0 guarantees the legacy filter is off in any browser that still honours the header, avoiding filter-based side channels. A strong CSP is the real defense against XSS.

Will 0 make my site less secure?

No. Modern browsers no longer ship the XSS Auditor, and where it did exist it caused more problems than it solved. Content Security Policy replaces it.

Related reading

Is X-XSS-Protection set on your site?

Scan any URL free to check X-XSS-Protection and every other security header.

Scan Now - Free