Browser headers are incomplete
HSTS, CSP, frame protection, Permissions-Policy, COOP and CORP were not observed. This reduces browser-side protection against clickjacking, script injection and cross-origin leakage.
nosniff ✓ referrer-policy ✓ CSP ✕ HSTS ✕