AVAILABLE6-month end-of-studies internship from February/March 2027

// SECURITY

How this site is protected

A portfolio is a small target, but it is also a statement. These are the protections in place, with the commands to check them yourself.

Last measured result

Mozilla Observatory: A+ (160 points, 12 of 12 tests passed), measured on 3 October 2026 on the live site.

Protections

Content-Security-Policy
Scripts, styles, images and fonts load from this site only (default-src 'none'). Trusted Types are required, so injected code cannot reach dangerous browser functions. Only one inline script is allowed, by its hash.
Subresource Integrity
Every script and stylesheet carries a hash computed at build time; the browser refuses a file that was altered.
Strict-Transport-Security
HTTPS only, for two years, with preload. The .dev domain is also on the browsers' built-in HTTPS-only list.
frame-ancestors, X-Frame-Options
The site cannot be embedded in another page, which blocks clickjacking.
COOP, COEP, CORP
The page runs isolated from other origins (cross-origin isolation), limiting side-channel attacks.
Permissions-Policy
Camera, microphone, location, USB and similar features are switched off.
Referrer-Policy: no-referrer
No address of this site is sent to the sites you open from it.
X-Content-Type-Options: nosniff
Browsers must respect the declared file types.
No cookies, no third parties
No tracker, no external font, no external script. Language and theme choices stay in your browser.
security.txt
A standard place to report a vulnerability.
Supply chain
Dependencies are audited on every change and every week, upgrades are proposed automatically, the build refuses forbidden settings, and no source maps are published.

Check it yourself

Read the headers from a terminal:

curl -sI https://www.mohamedfhafah.dev/ | grep -iE 'content-security|strict-transport|cross-origin|permissions|referrer|x-frame|x-content'
curl -s https://www.mohamedfhafah.dev/.well-known/security.txt

Independent scanners (they open in a new tab):

Visitor statistics

Page views are counted without cookies and without storing an IP address (path, referrer, country and device type only), to know which application links are opened.

Report a vulnerability

See security.txt, or write by email. Please do not publish details before I had time to answer.

security.txtmohamedfhafah975@gmail.com

Back to the home page