← All headersResponse header

What is an X-XSS-Protection header?

A now-deprecated header that used to enable a browser's built-in cross-site-scripting filter.

X-XSS-Protection used to toggle a browser's built-in cross-site-scripting filter, but that filter has since been removed from every major modern browser (it was actually found to introduce its own vulnerabilities in some cases), so the header itself no longer does anything meaningful. A properly configured Content-Security-Policy is the modern replacement for the protection this header used to offer.

Common use case

Older security header checklists and scanners still flag its absence, even though setting it today has no real effect in any current browser - a properly configured Content-Security-Policy is what actually matters now.

Example

X-XSS-Protection: 1; mode=block

History

Introduced by Microsoft in Internet Explorer 8 (2009), and adopted by Chrome and Safari's own built-in XSS auditors shortly after.

Deprecated / legacy status

Chrome removed its XSS Auditor entirely in 2019 after researchers found the filter itself could be abused to leak information and even introduce new XSS vulnerabilities in some edge cases; Firefox and Safari never implemented the equivalent feature at all, and the header is now a no-op everywhere.

Did you know?

It's a rare case of a security feature being actively removed from browsers because it turned out to make things less secure on balance, rather than simply falling out of fashion.