Security headers and cookies
Response headers tell browsers how to treat your site. Vigavo reads the headers of your homepage:
- hsts_missing: no
Strict-Transport-Security; browsers are not told to always use HTTPS. - csp_missing: no
Content-Security-Policy; nothing limits which scripts may run. Setting one needs testing so it does not block your own code. - frame_missing: no
X-Frame-Optionsorframe-ancestors; your page can be embedded in someone else's (clickjacking). - xcto_missing: no
X-Content-Type-Options: nosniff. - referrer_missing: no
Referrer-Policy; full page addresses leak to other sites. - permissions_policy_missing: no
Permissions-Policyfor camera, microphone, location and similar features. - cookie_flags (security): cookies without
Secure,HttpOnlyorSameSite. - server_version / powered_by: the server announces its software or exact version.
Most of these are set in one place: your host's or CDN's header settings, a next.config.js / vercel.json headers block, or the web server configuration. On hosted builders some headers are controlled by the platform: see Managed by your platform.
After changing headers, verify the fix with a new scan.
Last reviewed Oct 7, 2026, 12:00:00 AM