Open mrmatteastwood opened 3 years ago
You should check the browser response, because it's not producing those headers currently on your index when I visit https://snapflux.com/. It does produce those on your CSS/JS though.
Thanks for the pointer, and for following up. I still haven't gotten around to educating myself more on this, but I was always suspecting this was probably more of an issue on my end, due to my lack of understanding.
The following security headers are present in the .htaccess file for kait-solutions.de and snapflux.com:
Both websites receive an F score on securityheaders.com.
I am also using the WordPress plugin, "Shield Security" on both websites which has its own HTTP Security Headers module. With that exact same configuration, another one of my projects, hc-kartenlegen.de, gets a straight A.
Things I've tried
On kait-solutions.de, I tried a different(ly worded?) set of security headers, as follows:
I nicked those from a NextCloud I have on 2sinn.com (which gets an A), but even with them, kait-solutions.de still gets an F.
Note this may not be a bug, I'm quite possibly doing something wrong. I don't fully understand these codes. I researched them to the best of my abilities and cobbled them together from different sources.