Content Security Policy is not configured
What we observed
No Content-Security-Policy header was returned on the 4 pages included in this scan.
Why this matters
A well-configured CSP reduces the impact of certain browser-based injection attacks.
Affected pages: 3
Recommended action
Introduce a CSP gradually — start in report-only mode, then tune it to your app's real resources before enforcing.