missing_nosniff
X-Content-Type-Options: nosniff is missing
AuditLume examines one public response and its initial HTML. It does not perform a complete site audit.
Indicative impact: 4/100 · security
What it detects
The X-Content-Type-Options header is not exactly nosniff, ignoring case.
AuditLume examines one public response and its initial HTML. It does not perform a complete site audit.
Why it may matter
The signal helps prioritise a review because it may affect understanding, privacy, accessibility or technical protection. Its impact is indicative and must be interpreted in the page’s real context.
How to verify manually
Open the final URL and inspect the initial HTML and response headers with browser developer tools or curl. Repeat the check on representative templates and routes before drawing a conclusion.
The X-Content-Type-Options header is not exactly nosniff, ignoring case.
Cautious correction
Send nosniff and ensure correct Content-Type values for all resources before and after the change.
What it does NOT prove
This signal alone does not certify legal compliance or non-compliance, GDPR, WCAG or EAA; it is not a human or professional security audit and does not prove the presence or absence of all risk.