Missing Content-Security-Policy header
What this means
The response sends no Content-Security-Policy, so nothing constrains which scripts, styles and frames the page may load.
How to fix it
Add a policy appropriate to the site, starting in report-only mode to find violations before enforcing it.
Fix effort
This check needs a developer fix: it turns on a routing, hosting or infrastructure decision that no automatic edit can make safely.
Authoritative source
Find every page this affects
CrawlX runs this check — and 161 others — across your whole site, ranks the findings by estimated impact, and opens the fixable ones as pull requests. Free for 500 URLs.