1. 9
  1.  

  2. 1

    Helpful, I still missed the Referrer-Policy ;-)

    Before I used https://securityheaders.io/ which can also check.