Security headers protect your website from clickjacking, content injection, and data theft. This audit checks HTTPS encryption plus six critical HTTP response headers: Content-Security-Policy (CSP), Strict-Transport-Security (HSTS), X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy. Each missing header is scored, and fix code is provided for Nginx, Apache, and Express servers.