Checks

Referrer-Policy is unsafe

Referrer-Policy is an unsafe value that can send the full URL on cross-origin requests.

Why it matters

The path and query string can leak tokens or internal routes to other sites.

What to do

Use strict-origin-when-cross-origin, strict-origin, same-origin, or no-referrer.

Reference

A strict Referrer-Policy limits how much of the URL is sent to other origins.

MDN — Referrer-Policy