01 · Headers
What the server sends
Weighted by what each one actually prevents, not just whether it's present.
02 · The fix
Config to paste
Covers everything missing above. Read the notes before pasting — a strict policy on a WordPress site will break things if you don't check first.
03 · What it loads
Where the page pulls from
Read from the markup and from the stylesheets it links, so the policy above permits these rather than blocking them. Anything a script fetches at runtime won't appear here, which is why report-only first is worth the extra step.
04 · Raw
Everything it returned
The security-relevant headers as sent, including the ones that give away more than they should.