A round of hardening across the application.
Dependencies. Every known vulnerability in the production dependency tree is resolved — thirty advisories, now none. Most came from a duplicate copy of a framework that was installed to satisfy an out-of-date declaration in a third-party package and never actually loaded.
Response headers. The Content-Security-Policy now also refuses injected base tags, plugin content, and forms that would submit to another site — three ways an injected script could otherwise redirect a page's requests or a password.
Uploads. Account images are limited by size and file type, and deliberately do not accept SVG, which can carry script.
Passwords are now held to the same minimum everywhere. The server previously accepted shorter passwords than the sign-up form did.