A01Broken Access Control— X-Frame-Options, COOP, CORP, COEP
A02Cryptographic Failures— HTTPS, HSTS configuration
A03Injection— CSP, X-Content-Type-Options
A04Insecure Design— Server information disclosure
A05Security Misconfiguration— Referrer-Policy, Permissions-Policy, Cache-Control
A07XSS (Cross-Site Scripting)— X-XSS-Protection, CSP script-src
A08Software & Data Integrity— CDN detection, SRI hints
A09Logging & Monitoring— Report-To, NEL headers