So far seems like we can invest some time to improve several things:
- The HTTP headers in the website and discuss if we want to apply headers like: Content Security Policy, Strict Transport Policy, X-Content-Type-Options, X-Frame-Options, X-XSS-Protection...
- CA Authorization in the TLS layer
- Enable HSTS
- Add a
Security.Txtfile pointing to the current project security policy?
I used Web Check to do a fast review, so this is not yet an exhaustive list