Web Design and Development en Luxembourg
How we work in Luxembourg
Of five sites audited, the only one with a content policy
In an external audit of five websites, ours was the only one with a Content-Security-Policy in place, and properly built. That is not a medal: it is the normal state of the industry. That policy stops an injection from loading a script off someone else's domain, or a form from being posted somewhere else.
Having one forces you to keep loose code out
A real policy bans inline script and forces you to declare every external domain. That means no pasting a loose snippet into a template because you are in a hurry, and no adding a third-party tag without deciding to. What it costs is the way you build, not the header, and that is why almost nobody has one.
What ours still does not prevent
The webcoding.es policy still allows inline script, because the Google container and a hundred and fifty-one handlers sitting inside the templates need it. Moving them out to external files is a separate job we have not finished. A half-done policy still beats no policy, but we are not going to call it complete.
The rest of the header is set once
HSTS, nosniff, Referrer-Policy and a Permissions-Policy that denies camera, microphone, location and payment across the whole site. Half an hour of configuration that never gets touched again. We put them on every project because that is the real cost, and the alternative is looking bad in anyone's header report.
Answering your questions
What people ask us about Web Design and Development in Luxembourg.
If your question is not here, tell us about the project and we will answer with real context.
Ask us directlyReal work
Projects we have built
Full service · All the detail
Web Design and Development: stack, process, use cases and FAQs