Skip to main content
New: 190 SEO checks now available. See what's new
lowSecurityPERMISSIONS_POLICY_MISSING

Permissions-Policy header missing — the fix

This site does not send a Permissions-Policy (formerly Feature-Policy) HTTP header, which controls which browser features and APIs can be used on the page.

Where this fits: security in SEO

Security issues erode both rankings and trust. HTTPS has been a ranking signal since 2014, and browsers actively warn users away from insecure or mixed-content pages — a warning interstitial is a 100% bounce rate. Missing security headers rarely block indexing, but they widen your attack surface, and a hacked site (injected spam, malicious redirects) can be removed from results entirely. Security is the SEO work you do so you never have to do recovery work.

Why permissions-policy header missing hurts your rankings

Without a Permissions-Policy, any script on your page (including third-party scripts) can access powerful browser APIs like geolocation, camera, microphone, and payment. Restricting these permissions reduces the attack surface if a third-party script is compromised and protects user privacy.

This is a low-severity issue: a polish item. Fix it in batches during scheduled maintenance; the win is cumulative quality, not a step change.

How to fix it

Add a Permissions-Policy header that restricts browser features to only those your site actually uses. Disable features you do not need to prevent abuse by third-party scripts.

Permissions-Policy: camera=(), microphone=(), geolocation=(self), payment=(self)

Security best practices

  • Serve everything over HTTPS and redirect HTTP with a single 301.
  • Send HSTS, X-Content-Type-Options, and a Content-Security-Policy on every response.
  • Eliminate mixed content — one insecure asset breaks the padlock.
  • Keep dependencies and CMS plugins patched; most site hacks are known-CVE exploits.
  • Monitor Search Console's security section — Google often knows you're hacked before you do.

The full library: SEO best practices, by category.

Frequently asked questions

What does "Permissions-Policy header missing" mean?

This site does not send a Permissions-Policy (formerly Feature-Policy) HTTP header, which controls which browser features and APIs can be used on the page.

Why does permissions-policy header missing matter for SEO?

Without a Permissions-Policy, any script on your page (including third-party scripts) can access powerful browser APIs like geolocation, camera, microphone, and payment. Restricting these permissions reduces the attack surface if a third-party script is compromised and protects user privacy.

How do I fix permissions-policy header missing?

Add a Permissions-Policy header that restricts browser features to only those your site actually uses. Disable features you do not need to prevent abuse by third-party scripts.

How serious is this issue?

This is a low-severity issue: a polish item. Fix it in batches during scheduled maintenance; the win is cumulative quality, not a step change. It belongs to the security family of checks.

How do I find every page affected by this on my site?

Run a free Dr Urls audit: it crawls your site, detects permissions-policy header missing on every affected page, shows example URLs, and generates a ready-to-use fix task. Re-scan after fixing to verify the issue is gone.

Does your site have this issue?

A free Dr Urls audit crawls your site, finds every page affected by permissions-policy header missing, and hands you a ready-made fix task.

Check my site free

Related security guides