In order to improve the security of your site against some types of XSS (cross-site scripting) attacks, it is recommended that you add the following header to your site:
X-XSS-Protection: 1; mode=block
It is supported by IE (Internet Explorer) and Chrome. You can enable it by modifying your Apache settings or your
.htaccess file, and adding the following line to it:
Header set X-XSS-Protection "1; mode=block"
Or you can enable it automatically on WAF (along with other security headers) by setting "Additional Security Headers " to on. Note that it is enabled by default for all our customers.
If you have any questions, please contact our research team at firstname.lastname@example.org.