H
hostinger.com
CRO Recommendations — August 2026
1 Medium Site-Wide Security Verified by measurement

Missing security headers

6 of 6 standard security headers are absent, weakening protection against XSS, clickjacking and downgrade attacks.

CURRENT — Missing security headers
Screenshot
⚠ Missing security headersAll six standard security headers are absent, leaving the site vulnerable to XSS, clickjacking, and downgrade attacks.
Screenshot
Add security note
FixAdds a visible note under the main heading to highlight the missing headers and prompt implementation.
Both are photographs of the live page — the right side has the change applied in the browser.
Evidence

Observed on the live site Verified by measurement

✓ Flagged independently by 1 of 7 analysts
Business case

If this change wins

0.1 – 0.4
orders per 1,000 visitors
Medium
Effort — 2-5 days
Not A/B testable
At typical traffic
Detecting this needs about 1,941,808 visitors per variant. Ship it as a sequenced change and log the date instead.
Prioritisation

PXL score: 6 / 10

Assessed from the live page

QuestionAnswerPoints
Is the change above the fold?Yes1
Is the change noticeable in under 5 seconds?Yes2
Does it add or remove an element?Yes1
Does it run on a high-traffic page?Yes1
Verified by direct technical measurement?Yes1

Criteria that need your data

4 of these could not be answered from the live page. Session recordings, survey or support themes, and analytics access would raise the confidence of this ranking — they do not indicate a weaker finding.

QuestionAnswerPoints
Discovered via user testing?No0
Discovered via qualitative feedback (survey, support)?No0
Supported by heatmaps or session recordings?No0
Found via digital analytics or real-user field data?No0
Implementation

Hand this to your developer

Surface
Site-Wide Security — SITE-WIDE SECURITY
Problem
6 of 6 standard security headers are absent, weakening protection against XSS, clickjacking and downgrade attacks.
Current state
notes: missing: HSTS, CSP, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy
Change
notes: Add the missing headers at the CDN or web-server layer; HSTS and X-Content-Type-Options are one-line changes.
Acceptance criteria
GIVEN a first-time visitor on the affected page
WHEN the change is live
THEN Add the missing headers at the CDN or web-server layer; HSTS and X-Content-Type-Options are one-line changes, with no regression at 375px and 1280px widths.
Tracking
event: cro_missing_security_headers on interaction with the changed element; verify it fires in BOTH variants before opening traffic.
Success metric
conversion rate + bounce rate on the affected page
QA checklist
Chrome / Safari / Firefox · 375px + 1280px · keyboard reachable · screen-reader name present · no CLS introduced
Effort
Medium — 2-5 days
Test plan
1,941,808 visitors per variant (95% significance, 80% power); duration depends on traffic.
Rollback
Feature-flag the change; revert the flag if the primary metric drops for 3 consecutive days.
← OverviewLab LCP 14.2s mobile →