• The plugin seems to offer the option to add CSP headers and I’ve added to the default, thus:-

    upgrade-insecure-requests; default-src ‘self’; base-uri ‘none’; form-action ‘self’; frame-ancestors ‘none’; require-trusted-types-for ‘script’;

    When tested in securityheaders.com I’m getting A+ rating, nice, but I see that it only shows:-

    content-security-policy – frame-ancestors ‘self’;

    This is not the one I have entered. Have I entered and formatted the additional headers correctly?

    Additionally, the default headers: upgrade-insecure-requests; is not being shown. Are there issues here of have I misunderstood?

You must be logged in to reply to this topic.