1. Cross-origin resource sharing: arbitrary origin trusted
2. Cross-origin resource sharing
3. Input returned in response (reflected)
4. Cacheable HTTPS response
5. SSL certificate