Header evidence
Scans record the headers that the server returns so administrators can see relevant delivery/security signals.
SECURITY-HEADER DIAGNOSTICS · WordPress Plugin 2.0.0
How Omega Web Metrics WordPress Plugin 2.0.0 observes and reports response/security-header evidence.
Omega Web Metrics is diagnostic. It inspects available response/security header evidence as part of its server-side security and delivery analysis; it is not a security-header enforcement plugin.
Scans record the headers that the server returns so administrators can see relevant delivery/security signals.
The report is based on server/static evidence and does not claim that a header alone proves browser security or full security compliance.
Use the appropriate server configuration or a dedicated security product when a header needs to be changed.
A missing or unexpected header should be investigated in the context of the hosting stack, CDN/proxy, WordPress configuration and application requirements. Some controls such as HSTS and CSP are environment-sensitive and should not be enabled solely to improve a diagnostic score.
Use the Security category as evidence for review, not as a guarantee that a site is secure.
Review the complete public-facing capability specification, pricing and licence information for Omega Web Metrics.