Replace `ALLOWED_HOSTS = ["*"]` with the specific PythonAnywhere domain (`{username}.pythonanywhere.com`) to prevent host header attacks.