[### Username (e.g. epiz_XXX) or Website URL]
https://sedlescombegardensociety.org.uk
Error Message
Security headers scan shows the following headers missing:
Strict-Transport-Security
Content-Security-Policy
X-Frame-Options
X-Content-Type-Options
Referrer-Policy
Permissions-Policy
Other Information
All but one of these should be set by my Joomla System Plugin. Is the Server overriding or stripping them???
Oxy
April 22, 2022, 9:48am
2
Hi and welcome to the forum
online tools are blocked to protect users and servers
that’s why these tools throw out the wrong results
but you can always use your browser (dev tools = F12) and see the results
InfinityFree is a website hosting service. That means that the hosting accounts we provided are intended for hosting websites. Websites contain pages that are accessed through web browsers. InfinityFree is not intended to be used for file sharing, API hosting, database hosting or background tasks/tools.
To help enforce this, free hosting enforces a security system that makes sure that anyone trying to access your website is using a normal web browser. This is done by checking whether the web br…
5 Likes
I think unfortrunetely we can’t set HTTP Headers on subdomain, even for a test purpose. I tried for two days to set the headers but the scan keeps on showing that the headers are missing!
Finally i came to the conclusion, that it can’t work on a subdomain.
Admin
April 22, 2022, 4:25pm
4
Please see @Oxy ’s reply.
The headers are working fine, but the scanner is unable to read them correctly.
4 Likes
system
Closed
April 29, 2022, 4:25pm
5
This topic was automatically closed 7 days after the last reply. New replies are no longer allowed.