• Your plug-in isn’t detecting the security headers I have setup in Apache.

    X-Content-Type-Options
    X-XSS-Protection

    It detects X-Frame-Options and STS, but not the other two. I can see all the headers if I use any browser’s dev tools, so not sure why the plug-in won’t see them.

    This happens both locally (using MAMP) and on a staging site subdomain on a CentOS server.

  • The topic ‘No Detecting Security Headers’ is closed to new replies.