Security Headers with Helmet

Helmet 10,736 (MIT, helmetjs/helmet (https://github.com/helmetjs/helmet 10,736 ), 8.3.0) is fourteen tiny middlewares behind one call, thirteen of them enabled by helmet(); each sets or removes one response header. Mount it before every route, so even a 404 carries the headers.

Helmet's defaults, and the same call tuned for a JSON APIJavaScript
app.use(helmet());                        // the thirteen defaults, shown below
app.use(helmet({                          // ... or this instead, for a pure JSON API
  contentSecurityPolicy: { useDefaults: false,
    directives: { 'default-src': ["'none'"], 'frame-ancestors': ["'none'"] } },
  crossOriginResourcePolicy: { policy: 'cross-origin' },  // cover images for other sites
  strictTransportSecurity: { maxAge: 63072000, includeSubDomains: true, preload: true }
}));
Output
$ node probe.mjs http://localhost:3101/api/books      # no helmet
x-powered-by: Express
$ node probe.mjs http://localhost:3102/api/books      # helmet()
content-security-policy: default-src 'self';base-uri 'self';font-src 'self' https: data:;
  form-action 'self';frame-ancestors 'self';img-src 'self' data:;object-src 'none';
  script-src 'self';script-src-attr 'none';style-src 'self' https: 'unsafe-inline';
  upgrade-insecure-requests
cross-origin-opener-policy: same-origin
cross-origin-resource-policy: same-origin
origin-agent-cluster: ?1
referrer-policy: no-referrer
strict-transport-security: max-age=31536000; includeSubDomains
x-content-type-options: nosniff
x-dns-prefetch-control: off
x-download-options: noopen
x-frame-options: SAMEORIGIN
x-permitted-cross-domain-policies: none
x-xss-protection: 0

The x-powered-by line is gone - hidePoweredBy, which removes a fingerprinting hint, not a vulnerability. Two things surprise people. x-xss-protection: 0 deliberately disables the legacy XSS auditor, itself exploitable and gone from modern engines. And Cross-Origin-Embedder-Policy is not on by default, because require-corp breaks most third-party embeds; enable it only when you need SharedArrayBuffer. What each CSP directive means is Front-End Web Development material. The tuned call replaces the CSP with default-src 'none';frame-ancestors 'none' and extends HSTS to two years with preload.