Which headers it checks

The check makes a short-timeout HEAD request and reports whether Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, Referrer-Policy and Permissions-Policy are present.

A missing header is not always a serious issue — it depends on the application context — but they are usually a recommended improvement.