Platform may limit security headers
The detected hosted platform often cannot set arbitrary response headers such as HSTS or CSP.
Why it matters
A missing header on that platform can be a product limit rather than a forgotten server setting.
What to do
Check which headers the platform admin allows. Put a reverse proxy in front if you need headers it cannot set.
Reference
Observable stack and version details help attackers choose known exploits; outdated components should be upgraded.