Knowledge base

The 15 most common findings and what to do

The findings Vigavo reports most often, in order, with the short fix. Each links to its family article.

  1. caa_missing: add a CAA DNS record naming your certificate provider. DNS and email
  2. permissions_policy_missing: add Permissions-Policy: camera=(), microphone=(), geolocation=(). Headers
  3. ct_unavailable (info): the certificate-transparency lookup service did not answer during the scan; nothing to fix, it is retried next scan.
  4. security_txt_missing: publish /.well-known/security.txt with a contact email. Exposed files
  5. dkim_missing: add the DKIM record from your mail provider (may be a false alarm with unusual selector names). DNS and email
  6. csp_missing: add a Content-Security-Policy, tested so it does not block your own scripts. Headers
  7. secret_in_bundle: rotate the key, then move it to the server. Secrets in code
  8. robots_missing (SEO, info): add a robots.txt.
  9. referrer_missing: add Referrer-Policy: strict-origin-when-cross-origin. Headers
  10. frame_missing: add X-Frame-Options: SAMEORIGIN or frame-ancestors in the CSP. Headers
  11. xcto_missing: add X-Content-Type-Options: nosniff. Headers
  12. og_missing (SEO): add og:title, og:description and og:image meta tags.
  13. dmarc_missing: add a DMARC record, starting with p=none. DNS and email
  14. hsts_missing: add Strict-Transport-Security. Headers
  15. cookie_flags: add Secure, HttpOnly and SameSite to cookies. Headers

If a finding says it is managed by your platform, read Managed by your platform first.

Last reviewed Oct 7, 2026, 12:00:00 AM

Still stuck? Send a ticket

Feedback
Type