Header set X-Frame-Options "DENY"
Header set X-Content-Type-Options "nosniff"
Header set Content-Security-Policy "default-src 'self'; img-src *; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'"
Header set X-XSS-Protection "0"
Header set Cache-Control "max-age=2592000
Header set Cache-Control "max-age=0"