I know this is a old topic, but this got in the why over the last 2+ years. ;D
I finally am moving up the security to the .htaccess file on my website.
Found this website to help me out - http://www.insertcart.com/how-to-secure-website-made-these-changes-in-htaccess/
[php]
Security improvements
Header unset Server
#Header unset X-Pingback
Header unset Accept-Ranges
<FilesMatch ".html>
Header set X-Frame-Options “SAMEORIGIN”
BrowserMatch MSIE ie
Header set Imagetoolbar "no" env=ie
Header set X-Content-Type-Options "nosniff" env=ie
Header set X-UA-Compatible "IE=edge" env=ie
Header set X-XSS-Protection "1;mode=block" env=ie
Header set X-Content-Security-Policy "default-src 'self'; img-src 'self' analytics.example.com; \
script-src 'self' analytics.example.com ajax.googleapis.com; font-src 'self' data:" env=ie
BrowserMatch Firefox ff
Header set Content-Security-Policy "default-src 'self'; img-src 'self' analytics.example.com; \
script-src 'self' analytics.example.com ajax.googleapis.com; \
font-src 'self' data:" env=ff
BrowserMatch SAFARI safari
Header set X-XSS-Protection "1;mode=block" env=safari
Header set X-WebKit-CSP "default-src 'self'; img-src 'self' analytics.example.com; \
script-src 'self' analytics.example.com ajax.googleapis.com; font-src 'self' data:" env=safari
BrowserMatch CHROME ch
Header set X-Content-Type-Options "nosniff" env=ch
Header set X-WebKit-CSP "default-src 'none'; img-src 'self' analytics.example.com; \
script-src 'self' analytics.example.com ajax.googleapis.com; font-src 'self' data:" env=ch
BrowserMatch chromeframe chf
Header set Imagetoolbar "no" env=chf
Header set X-Content-Type-Options "nosniff" env=chf
Header set X-UA-Compatible "IE=edge,chrome=1" env=chf
Header set X-XSS-Protection "1;mode=block" env=chf
Header set X-WebKit-CSP "default-src 'none'; img-src 'self' analytics.example.com; \
script-src 'self' analytics.example.com ajax.googleapis.com; font-src 'self' data:" env=chf
[/php]