// SECURITY
How this site is protected
A portfolio is a small target, but it is also a statement. These are the protections in place, with the commands to check them yourself.
Last measured result
Mozilla Observatory: A+ (160 points, 12 of 12 tests passed), measured on 3 October 2026 on the live site.
Protections
- Content-Security-Policy
- Scripts, styles, images and fonts load from this site only (default-src 'none'). Trusted Types are required, so injected code cannot reach dangerous browser functions. Only one inline script is allowed, by its hash.
- Subresource Integrity
- Every script and stylesheet carries a hash computed at build time; the browser refuses a file that was altered.
- Strict-Transport-Security
- HTTPS only, for two years, with preload. The .dev domain is also on the browsers' built-in HTTPS-only list.
- frame-ancestors, X-Frame-Options
- The site cannot be embedded in another page, which blocks clickjacking.
- COOP, COEP, CORP
- The page runs isolated from other origins (cross-origin isolation), limiting side-channel attacks.
- Permissions-Policy
- Camera, microphone, location, USB and similar features are switched off.
- Referrer-Policy: no-referrer
- No address of this site is sent to the sites you open from it.
- X-Content-Type-Options: nosniff
- Browsers must respect the declared file types.
- No cookies, no third parties
- No tracker, no external font, no external script. Language and theme choices stay in your browser.
- security.txt
- A standard place to report a vulnerability.
- Supply chain
- Dependencies are audited on every change and every week, upgrades are proposed automatically, the build refuses forbidden settings, and no source maps are published.
Check it yourself
Read the headers from a terminal:
curl -sI https://www.mohamedfhafah.dev/ | grep -iE 'content-security|strict-transport|cross-origin|permissions|referrer|x-frame|x-content' curl -s https://www.mohamedfhafah.dev/.well-known/security.txt
Independent scanners (they open in a new tab):
Visitor statistics
Page views are counted without cookies and without storing an IP address (path, referrer, country and device type only), to know which application links are opened.
Report a vulnerability
See security.txt, or write by email. Please do not publish details before I had time to answer.