Main website
Government Drupal Developers NetworkCommunity
Resource library
Guide

Hardening security headers with SecKit

A sensible Content-Security-Policy, HSTS and clickjacking setup for government sites.

5
BC
Ben Carter

Government Digital Service · 26 Jul 2026

Open drupal.org(opens in a new tab)

Install

composer require drupal/seckit
drush en seckit -y

Recommended baseline

# config/sync/seckit.settings.yml (excerpt)
seckit_xss:
  csp:
    checkbox: true
    default-src: "'self'"
    script-src: "'self' https://www.googletagmanager.com"
    frame-ancestors: "'none'"
seckit_ssl:
  hsts: true
  hsts_max_age: 31536000
  hsts_subdomains: true

Start in report-only mode for a week, review the reports, then enforce.

Join GDDN to upvote and share your own resources.