OWASP Secure Headers Project

Provides technical information and tools about HTTP security headers.

About OWASP Secure Headers Project

ℹ️ Purpose

The OWASP Secure Headers Project (also named OSHP) describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities. The OSHP intends to raise awareness and use of these headers.

πŸ“– Content

While this page serves as the project’s official OWASP identity card, the GitHub repository remains the sole source of truth. All master data and project content are managed and hosted exclusively on GitHub.

Project Leaders

Ricardo Iramar

πŸ§‘β€πŸ’» Project leader

EmailLinkedIn

Dominique Righetto

πŸ§‘β€πŸ’» Project leader

EmailLinkedIn

Project Information

Production Project
Classification
Tool
Language
English
License
Apache 2.0
Contributors
25
GitHub Stars
217
Industry Usage
FinanceHealthIndustry
OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
Β© 2026, OWASP Foundation Inc. All rights reserved.