Valid Referrer Policy
0 Intentional IssuesA page whose referrer policy is declared once, through the meta tag, using the token the specification recommends.
Expected result: meta_name_referrer NOT DETECTED
And referrer_policy_header (#70) not detected either. That pairing is the whole fixture: the retired check and the live one used to report the same correctly configured policy twice. One declaration, in one place, should now produce nothing from either.
Referrer Policy tokens
strict-origin-when-cross-origindeclared hereDeclared on this page. The browser default and the value the specification recommends.
no-referrerAlso valid, and stricter. Sends nothing at all; correct for pages that must leak no context.
same-originAlso valid. Full referrer within the origin, nothing across it.
strict-originAlso valid. Origin only, and nothing at all on an https-to-http downgrade.
Negative counterpart: /head-tag-gaps declares no referrer tag, and /security-headers is where the missing-header side of #70 lives. Index: /false-positive-fixtures.