1 article with this tag
More headers is not better. Sort them into three groups: still effective (CSP, HSTS, X-Frame-Options, nosniff, Referrer-Policy, Permissions-Policy), obsolete (Expect-CT has been mostly obsolete since June 2021), and actively harmful (MDN marks X-XSS-Protection deprecated and non-standard and warns it can create XSS vulnerabilities in otherwise safe sites). Copy a stale list and you import the harmful settings along with the good ones.