Trust and structured data

Security response headers

This check records baseline headers that restrict unsafe loading and interpretation of a page.

01

What is measured

The audit looks for CSP, HSTS, X-Content-Type-Options, Referrer-Policy, Permissions-Policy and frame protection.

02

Pass criterion

Production responses contain a meaningful set that matches the website’s actual resources and features.

03

What to fix

Add policies at the reverse proxy or application layer and test them in report-only mode before strict enforcement.

04

Automation limit

A present header does not prove that its value is effective; an overly broad policy can create false confidence.

Reference

Official documentation

OWASP Secure Headers Project

Check this and every other signal

Start the free audit