Important security headers for Fastify. It is a tiny wrapper around helmet. Usage: Simply require this plugin, and the basic security headers will be set. const fastify = require('fastify')() const helmet = require('@fastify/helmet') fastify.register( helmet, // Example disables the `contentSecurityPolicy` middleware but keeps the rest. { contentSecurityPolicy: false } ) fastify.listen({ port: 3000 }, err => { if (err) throw err }) How it works: @fastify/helmet is a tiny wrapper around helmet that adds an 'onRequest' hook and a reply.helmet decorator. It accepts the same options as helmet, and you can see more in the helmet documentation. Apply Helmet to all your application routes: By passing { global: true } into the options, @fastify/helmet allows you to register Helmet for all your application routes by default. If you want a more granular control on how to apply Helmet to your application you can choose to disable it on a global scope by passing { global: false } to the options. By default, this option is set to true. Example - enable @fastify/helmet globally: fastify.register(helmet) // or fastify.register(helmet, { global: true })
FEATURES
ALTERNATIVES
A web-based tool for instrumenting and analyzing Android applications using Flask, Jinja, and Redis.
Backslash Security is an application security platform that uses reachability analysis to enhance SAST and SCA, prioritize vulnerabilities, and provide remediation guidance.
Static code analyzer for Infrastructure as Code with 500+ security policies and support for various IaC tools and cloud platforms.
Python-based web server framework for setting up fake web servers and services with precise data responses.
A fake Django admin login screen to detect and notify admins of attempted unauthorized access
Detect trojan source attacks that employ unicode bidi attacks to inject malicious code.
XSS Polyglot Challenge - XSS payload running in multiple contexts for testing XSS.
A tool for secure content publishing and verification using offline signing and trusted collections.
PINNED
data:image/s3,"s3://crabby-images/9e249/9e2491757370fdcf2c6dfbd4da3527a8337bd01f" alt="InfoSecHired Logo"
InfoSecHired
An AI-powered career platform that automates the creation of cybersecurity job application materials and provides company-specific insights for job seekers.
data:image/s3,"s3://crabby-images/6a2c6/6a2c67d7e31951ef9f2e6915d85dbf40b01c0d62" alt="Mandos Brief Newsletter Logo"
Mandos Brief Newsletter
A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.
data:image/s3,"s3://crabby-images/7f604/7f604770dc9caf20978be2c218900c63f20baa45" alt="Kriptos Logo"
Kriptos
An AI-driven data classification and governance platform that automatically discovers, analyzes, and labels sensitive information while providing risk management and compliance capabilities.
data:image/s3,"s3://crabby-images/4d0dc/4d0dc8e814a6fcdfe4c019db0029abadf06395b9" alt="System Two Security Logo"
System Two Security
An AI-powered platform that automates threat hunting and analysis by processing cyber threat intelligence and generating customized hunt packages for SOC teams.
data:image/s3,"s3://crabby-images/e04f7/e04f786349599980dff4c5e219fec6ee5a365e36" alt="Aikido Security Logo"
Aikido Security
Aikido is an all-in-one security platform that combines multiple security scanning and management functions for cloud-native applications and infrastructure.
data:image/s3,"s3://crabby-images/76c63/76c63737151c33acc25c2fc8837184fc23f6e345" alt="Permiso Logo"
Permiso
Permiso is an Identity Threat Detection and Response platform that provides comprehensive visibility and protection for identities across multiple cloud environments.
data:image/s3,"s3://crabby-images/2a583/2a583456e23215cedfe6d2020b2ee1e33acfc4a1" alt="Wiz Logo"
Wiz
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.
data:image/s3,"s3://crabby-images/176e2/176e2a0954fdd732bf6c44c134d0abdba2c19c66" alt="Adversa AI Logo"
Adversa AI
Adversa AI is a cybersecurity company that provides solutions for securing and hardening machine learning, artificial intelligence, and large language models against adversarial attacks, privacy issues, and safety incidents across various industries.