What the issue means
A missing Referrer-Policy header can leak full URLs to third-party sites and analytics destinations.
Security fix guide
A missing Referrer-Policy header can leak full URLs to third-party sites and analytics destinations.
Run Full Website Security ScanA missing Referrer-Policy header can leak full URLs to third-party sites and analytics destinations.
URLs can contain paths, IDs, search terms, and tokens. A referrer policy limits what browsers send cross-origin.
Inspect response headers for Referrer-Policy.
Use strict-origin-when-cross-origin for a balanced default, or no-referrer for sensitive apps.
add_header Referrer-Policy "strict-origin-when-cross-origin" always;Header always set Referrer-Policy "strict-origin-when-cross-origin"headers: async () => [{ source: "/(.*)", headers: [{ key: "Referrer-Policy", value: "strict-origin-when-cross-origin" }] }]Add Referrer-Policy with a response header modification rule.