These are fantastic tips, thanks for sharing this Maggie! build secure applications is especially hard in these days, I remember once I read an article that explained how it's possible to stole data using CSS since then I implemented a CSP in my website, and I keep an eye in the OWASP list as well, actually is almost impossible to keep the full security using external plugins etc.