What it checks
Whether responses set a Permissions-Policy header that switches off powerful browser features the site does not use.
A pass means: A Permissions-Policy limits powerful browser features.
Possible findings
No Permissions-Policy
Severity: InformationConfidence: ConfirmedKind: Recommended hardening
What we found
Responses do not set a Permissions-Policy header.
Why it matters
A Permissions-Policy switches off browser features (camera, microphone, geolocation) your site does not use, limiting what injected or third-party code could do.
How to fix it
Add a policy that disables features you do not use, for example Permissions-Policy: camera=(), microphone=(), geolocation=().

