- CSP
- A response header (Content-Security-Policy) that limits which sources may run scripts or load content.
- HSTS
- HTTP Strict Transport Security: tells browsers to use HTTPS only for a host.
- TLS
- Transport Layer Security: the encryption protocol behind HTTPS.
- SPF / DKIM / DMARC
- Email authentication standards that stop others from sending mail as your domain.
- CAA
- DNS record naming the certificate authorities allowed to issue certificates for the domain.
- DNSSEC
- Cryptographic signing of DNS answers to prevent spoofing.
- SRI
- Subresource Integrity: a hash on a script tag so a modified third-party file is refused.
- CWE
- Common Weakness Enumeration: MITRE's catalog of software weakness types.
- OWASP Top 10
- The Open Worldwide Application Security Project's list of the most critical web risks.
- WCAG
- Web Content Accessibility Guidelines; Level AA is the common legal benchmark.
- TTFB
- Time to First Byte: delay before the server starts sending the page.
- LCP
- Largest Contentful Paint: when the main content becomes visible (good ≤ 2.5 s).
- CLS
- Cumulative Layout Shift: visual stability while loading (good ≤ 0.1).
- TBT / INP
- Total Blocking Time (lab) and Interaction to Next Paint (field): responsiveness to input.
- Canonical URL
- The preferred URL for a page when duplicates exist.
- Structured data
- Machine-readable JSON-LD describing page content for search engines.
- Open Graph
- Metadata that controls link previews on social and messaging apps.
- Lab vs field data
- Lab data is a controlled single test; field data is measured from real visitors.