Checks

Cross-Origin-Opener-Policy (COOP) is present

The response includes Cross-Origin-Opener-Policy.

Why it matters

COOP decides whether other windows can keep a reference to this page through window.opener.

What to do

unsafe-none leaves the page in a shared browsing context. That is a separate result.

Reference

Security response headers reduce XSS, clickjacking, and protocol downgrade risk.

OWASP Secure Headers Project