What it checks
Whether responses carry X-Content-Type-Options: nosniff, which stops browsers guessing a file type and running it as something else.
A pass means: Browsers are told not to guess content types.
Possible findings
X-Content-Type-Options is not set
Severity: LowConfidence: ConfirmedKind: Recommended hardening
What we found
Responses do not include X-Content-Type-Options: nosniff.
Why it matters
Without it, browsers may guess a file's type and run content as script that was meant to be plain text or an image.
How to fix it
Add X-Content-Type-Options: nosniff to all responses.

