lowmissing-x-content-type-optionschecked on every page we scan

Missing or invalid X-Content-Type-Options header

Without nosniff, browsers guess at a file's type when the declared one looks wrong.

Why it matters

Without nosniff, browsers guess at a file's type when the declared one looks wrong. An uploaded file served as plain text can be reinterpreted as JavaScript and executed in your users' browsers. This matters most if you accept uploads, and costs one header either way.

How ShipReady detects it

Shared tables and rules for the two halves below. Split because this check was a hybrid: nine rules read the headers of a response we already have, which genuinely differ between routes, while missing-https-redirect probes the http:// equivalent of the origin — one fact, and running it per page would issue the same request ten times.

Detection is deterministic. ShipReady reports this only when it observes the condition directly, and prefers to miss a real problem over inventing one. Rule version 1.3.0.

How to fix it

This is the prompt ShipReady puts in your report — written to be pasted straight into Cursor, Claude Code, or whichever assistant built the app.

Add X-Content-Type-Options: nosniff to prevent MIME-sniffing.

Frequently asked questions

What does "Missing or invalid X-Content-Type-Options header" mean?
Without nosniff, browsers guess at a file's type when the declared one looks wrong.
How serious is it?
ShipReady rates this low. Worth fixing. Small individually, and they accumulate.
How do I fix it?
Paste the fix prompt on this page into Cursor, Claude Code or your AI editor. It is the same prompt ShipReady puts in your report.
Can I check my own site?
Yes — ShipReady scans up to ten pages of any public site for free and reports this alongside every other check.

Related checks

Does your site have this?

ShipReady checks this and 73 other things across up to ten pages of your site. Free, no signup.

Scan my site