Permissions-Policy
Permissions-Policy lets you control which browser features — like camera, microphone and location — your site and its embedded content are allowed to use.
What it is
Modern browsers expose powerful features to websites: camera, microphone, geolocation, and more. The Permissions-Policy header lets you explicitly allow or deny each of these, both for your own site and for any third-party content embedded in it.
By default, many of these features are available unless you turn them off. This header lets you disable the ones you don't need.
Why it matters
If your site includes third-party scripts or embeds, they may be able to request access to sensitive features on your behalf. A Permissions-Policy shuts the door on features you don't use, reducing what a compromised or malicious embed could attempt.
How Pentrawl checks it
Pentrawl checks your response headers for a Permissions-Policy header. Its presence passes the check; its absence is reported as a low-severity issue.
How to fix it
Add a Permissions-Policy header to your server, disabling the features your site doesn't use. The example below blocks camera, microphone and geolocation entirely.
Permissions-Policy: camera=(), microphone=(), geolocation=()