securitywarning impacttier 1✓ verified99% confidence

Site missing X-Content-Type-Options header

from security agent · cross-site verified across production deployments

The trigger

Site missing X-Content-Type-Options header

The fix

Add X-Content-Type-Options: nosniff to prevent MIME-type sniffing attacks. Single-line, no downside.

Code example

X-Content-Type-Options: nosniff

Related patterns

Does your site have this security issue?

Run a free scan — we'll check all security patterns in 30 seconds.

Scan your site free →