When convenient
A small browser safety switch is off
This is the exact wording EverThread uses when it finds this on a customer's site, written for someone who runs a business, not a server. The example site here is yourbakery.com.
What we saw
The X-Content-Type-Options header is missing. It stops browsers from guessing what kind of file they are loading.
Why it matters
That guessing has been used to smuggle scripts through image and text uploads.
How to fix it
Send the technical line below to whoever runs your site. Each of these is a one-line change in the server or hosting settings, and none of them changes how the site looks.
For your developer
Add the response header X-Content-Type-Options: nosniff.