A recent security scan reveiled the following findings and I would like to ask if any or all can be resolved on Cloudflare:
• HTML Security Issues:
Problems detected in the web page HTML. - Do not use any HTTP resources over HTTPS
• Ineffective headers: X-Frame-Options:
The implementation of these header(s) do not follow security best practices. - Ensure your headers are implemented correctly, as outlined in http_s://tools.ietf.org/html/rfc7231. Your headers should not permit caching of encrypted content. They should also have specific permissions (as opposed to using wildcards or other generalizations) and be formatted properly
• Missing required headers:
One or more required security headers are not set. - Ensure your policy correctly implements the required headers. Refer to the http_s://help.bitsighttech.com/hc/en-us/articles/360008632054