* Shift+click on host name, and pull up info on trustability from NoScript.net database
* Filters WebGL, XSLT, @font-face
* Sophisticated XSS protection: Look up XSS on these pages:
* CSRF protection
* Clearclick: Detects invisible elements which cover clicked visible elements
https://hackademix.net/2008/10/08/hello-clearclick-goodbye-c...
* A pretty sophisticated firewall in your browser, Application Boundaries Enforcer (ABE), where you can even write your own policies:
"Living inside the browser, the ABE component can take advantage of its privileged placement for enforcing web application boundaries, because it always knows the real origin of each HTTP request"
"Many of the threats NoScript is currently capable of handling, such as XSS, CSRF or ClickJacking, have one common evil root: lack of proper isolation at the web application level."
"The idea behind the Application Boundaries Enforcer (ABE) module is hardening the web application oriented protections ... by delivering a firewall-like component running inside the browser ... specialized in defining and guarding the boundaries of each sensitive web application"
More here: https://noscript.net/abe/
Also, there's a project to create a GUI for just the ABE component, called SABER