Skip to main content
UNPWNED
Bolt.new Security Guide
Q&ABolt.new

What security headers does Bolt.new set?

Bolt.new typically does not configure security headers in the generated application code. Headers like Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, and Permissions-Policy are usually absent. These headers are essential for preventing cross-site scripting, clickjacking, MIME sniffing, and other browser-based attacks. The deployment platform may add some basic headers, but a comprehensive security header configuration must be added manually. UNPWNED performs its own local header assessment using public industry guidance.

Check your Bolt.new app now

Run free security scan

Last reviewed: 2026-04-07. Based on publicly available security research and UNPWNED scan telemetry.