Infosecurity
Referrer-Policy is not set
The full URL of your pages is sent to every external site a visitor clicks through to, including query strings.
Next step
Set referrer-policy: strict-origin-when-cross-origin explicitly.
Evidence
referrer-policy header absent on all responses · default: strict-origin-when-cross-origin varies by browser
Details
- Affected
- yourwebsite.com
- Occurrences
- 1 time
- First seen
- 16 days ago
- Category
- security