The 15 most common findings and what to do
המאמר עדיין לא תורגם; הוא מוצג באנגלית.
The findings Vigavo reports most often, in order, with the short fix. Each links to its family article.
- caa_missing: add a CAA DNS record naming your certificate provider. DNS and email
- permissions_policy_missing: add
Permissions-Policy: camera=(), microphone=(), geolocation=(). Headers - ct_unavailable (info): the certificate-transparency lookup service did not answer during the scan; nothing to fix, it is retried next scan.
- security_txt_missing: publish
/.well-known/security.txtwith a contact email. Exposed files - dkim_missing: add the DKIM record from your mail provider (may be a false alarm with unusual selector names). DNS and email
- csp_missing: add a Content-Security-Policy, tested so it does not block your own scripts. Headers
- secret_in_bundle: rotate the key, then move it to the server. Secrets in code
- robots_missing (SEO, info): add a
robots.txt. - referrer_missing: add
Referrer-Policy: strict-origin-when-cross-origin. Headers - frame_missing: add
X-Frame-Options: SAMEORIGINorframe-ancestorsin the CSP. Headers - xcto_missing: add
X-Content-Type-Options: nosniff. Headers - og_missing (SEO): add
og:title,og:descriptionandog:imagemeta tags. - dmarc_missing: add a DMARC record, starting with
p=none. DNS and email - hsts_missing: add
Strict-Transport-Security. Headers - cookie_flags: add
Secure,HttpOnlyandSameSiteto cookies. Headers
If a finding says it is managed by your platform, read Managed by your platform first.
נבדק לאחרונה 7 באוק׳ 2026, 0:00:00