X-XSS-Protection

HTTP response header

X-XSS-Protection enables browser cross-site scripting filter

Header usage statistics

X-XSS-Protection response header information and usage statistics.
Websites using header X-XSS-Protection6,609,065
Percentage of websites that use X-XSS-Protection header10.58%
Total discovered header valuesMore than 10,000
Header uses directivesYes
Header values are unique or randomNo
Most popular in the country United States

X-XSS-Protection directives (4 total)

  • 0
  • 1
  • mode
  • report

X-XSS-Protection Directives

X-XSS-Protection directives value information and usage statistics
DirectiveShareWebsites countUnique Values
190.53%5,983,0853
mode87.62%5,790,70814
09.38%619,7092
report2.12%140,075172

Websites utilizing X-XSS-Protection

List of websites that use X-XSS-Protection header
DomainCountryRankContacts
fonts.googleapis.com United States1
facebook.com United States2
google.com United States3
youtube.com United States6
twitter.com United States7
googletagmanager.com United States8
See full domain list

Common header values

List of top common X-XSS-Protection header values
Header valueValue prevalence
1; mode=block81.08%
07.51%
14.48%
1;mode=block2.48%
"1; mode=block"1.46%
0;report=https://cdn.website-start.de/app/reporting/policyviolation/submit1.39%
1; mode=block;0.36%
1; mode=block0.22%
0;report=https://cdn.initial-website.com/app/reporting/policyviolation/submit0.21%
1; mode-block0.12%
value=1; mode=block0.12%
1; mode=block; report=/beacon/csp.php0.05%
"1; mode=block" always0.04%
0;report=https://cdn.eu.mywebsite-editor.com/app/reporting/policyviolation/submit0.03%
1; mode=block; report=/csr.php0.03%
0; mode=block0.03%
1;0.01%
1;mod=block0.01%
0;0.01%
1; mode = block0.01%