Skip to main content
Resources
Web Platform
Dive into the web platform, at your pace.
HTML
CSS
JavaScript
User experience
Learn how to build better user experiences.
Performance
Accessibility
Identity
Learn
Get up to speed on web development.
Learn HTML
Learn CSS
Learn JavaScript
Learn AI
Learn Performance
Learn Accessibility
More courses
Additional resources
Explore content collections, patterns, and more.
AI and the web
Explore
PageSpeed Insights
Podcasts & shows
Developer Newsletter
About web.dev
Discover
Baseline
How to use Baseline
Blog
Case Studies
/
English
Deutsch
Español – América Latina
Français
Indonesia
Italiano
Polski
Português – Brasil
Tiếng Việt
Türkçe
Русский
עברית
العربيّة
فارسی
हिंदी
বাংলা
ภาษาไทย
中文 – 简体
中文 – 繁體
日本語
한국어
Sign in
Articles
AI and the web
Fast load times
Learn Core Web Vitals
Identity
Progressive Web Apps
Payments
Notifications
How to optimize INP
Network reliability
React
Animations
Mini apps
Media
Safe and secure
WebAssembly
Devices
Easily discoverable
Test automation
Angular
Resources
More
AI and the web
Fast load times
Learn Core Web Vitals
Identity
Progressive Web Apps
Payments
Notifications
How to optimize INP
Network reliability
React
Animations
Mini apps
Media
Safe and secure
WebAssembly
Devices
Easily discoverable
Test automation
Angular
Discover
Baseline
How to use Baseline
Blog
Case Studies
Understand security basics
Security should not be so scary!
What are security attacks?
Understanding "same-site" and "same-origin"
Security headers quick reference
Secure connections with HTTPS
Why HTTPS matters
Enabling HTTPS on your servers
What is mixed content?
Fixing mixed content
When to use HTTPS for local development
How to use HTTPS for local development
Prevent info leaks
Browser sandbox
Same-origin policy
Cross-Origin Resource Sharing (CORS)
Making your website "cross-origin isolated" using COOP and COEP
Why you need "cross-origin isolated" for powerful features
Protect your resources from web attacks with Fetch Metadata
Protect websites from XSS
Prevent DOM-based cross-site scripting vulnerabilities with Trusted Types
Mitigate cross-site scripting (XSS) with a strict Content Security Policy (CSP)
Securely hosting user data in modern web applications
Protect users from tracking
Understanding cookies
SameSite cookies explained
SameSite cookie recipes
First-party cookie recipes
Referer and Referrer-Policy best practices
User-agent client hints
Schemeful Same-Site
Monitor security violations and deprecations
Reporting API
Migrate to Reporting API v1
Network Error Logging (NEL)
Help! I've been hacked
Help, I think I've been hacked
How do I know if my site was hacked?
Top ways sites get hacked by spammers
Build a support team
Quarantine your site
Use Search Console
Assess spam damage
Fix the Japanese Keyword hack
Fix the gibberish hack
Fix the cloaked keywords and links hack
Hacked with malware
Identify the vulnerability
Clean and maintain your site
Request a review
Glossary for hacked sites
FAQ for hacked sites
Web Platform
HTML
CSS
JavaScript
User experience
Performance
Accessibility
Identity
Learn
Learn HTML
Learn CSS
Learn JavaScript
Learn AI
Learn Performance
Learn Accessibility
More courses
Additional resources
AI and the web