P3 · LowSecurity
Missing Referrer-Policy
No referrer policy set
Code: missing_referrer_policy
Why it matters
No referrer policy set. Browsers and users expect sites to be secure. Missing protections expose visitors to data theft, phishing, and loss of trust.
How to fix
Add Referrer-Policy header
http# Nginx — add inside your server {} block
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
# Apache — add to .htaccess or <VirtualHost>
Header always set Referrer-Policy "strict-origin-when-cross-origin"Related checks in Security
Run a free scan to check your site
Get a complete audit in under 2 minutes. No account required.
Start Free Scan