What it checks
Whether responses set a Referrer-Policy header that limits how much of the page address is shared with other sites.
A pass means: A Referrer-Policy limits what is shared with other sites.
Possible findings
No Referrer-Policy
Severity: InformationConfidence: ConfirmedKind: Recommended hardening
What we found
Responses do not set a Referrer-Policy header.
Why it matters
Modern browsers default to a reasonable policy, so the risk is small. Setting one explicitly stops full URLs, which can contain identifiers, leaking to other sites.
How to fix it
Add Referrer-Policy: strict-origin-when-cross-origin.

