Check which security headers your site sets and get a grade. Missing headers are a common OWASP misconfiguration finding.
Security headers tell browsers how to handle your site's content. Missing headers - especially CSP and HSTS - are consistently found in penetration tests and listed under OWASP A05: Security Misconfiguration.