Helmet 10,736 (MIT, helmetjs/helmet (https://github.com/helmetjs/helmet 10,736 ), 8.3.0) is fourteen tiny middlewares behind one call, thirteen of them enabled by helmet(); each sets or removes one response header. Mount it before every route, so even a 404 carries the headers.
app.use(helmet()); // the thirteen defaults, shown below
app.use(helmet({ // ... or this instead, for a pure JSON API
contentSecurityPolicy: { useDefaults: false,
directives: { 'default-src': ["'none'"], 'frame-ancestors': ["'none'"] } },
crossOriginResourcePolicy: { policy: 'cross-origin' }, // cover images for other sites
strictTransportSecurity: { maxAge: 63072000, includeSubDomains: true, preload: true }
}));$ node probe.mjs http://localhost:3101/api/books # no helmet x-powered-by: Express $ node probe.mjs http://localhost:3102/api/books # helmet() content-security-policy: default-src 'self';base-uri 'self';font-src 'self' https: data:; form-action 'self';frame-ancestors 'self';img-src 'self' data:;object-src 'none'; script-src 'self';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'; upgrade-insecure-requests cross-origin-opener-policy: same-origin cross-origin-resource-policy: same-origin origin-agent-cluster: ?1 referrer-policy: no-referrer strict-transport-security: max-age=31536000; includeSubDomains x-content-type-options: nosniff x-dns-prefetch-control: off x-download-options: noopen x-frame-options: SAMEORIGIN x-permitted-cross-domain-policies: none x-xss-protection: 0
The x-powered-by line is gone - hidePoweredBy, which removes a fingerprinting hint, not a vulnerability. Two things surprise people. x-xss-protection: 0 deliberately disables the legacy XSS auditor, itself exploitable and gone from modern engines. And Cross-Origin-Embedder-Policy is not on by default, because require-corp breaks most third-party embeds; enable it only when you need SharedArrayBuffer. What each CSP directive means is Front-End Web Development material. The tuned call replaces the CSP with default-src 'none';frame-ancestors 'none' and extends HSTS to two years with preload.