Description
The HTTP Public-Key-Pins response header was used to associate a specific cryptographic public key with a web server to mitigate the risk of MITM attacks with forged certificates. However, it has been deprecated and is no longer supported by modern browsers.
Recommendation
Consider removing the Public-Key-Pins header and instead use the Expect-CT header along with Certificate Transparency to enhance security against MITM attacks.
References
Could your website be exposed too?
SmartScanner can check your website for Public-Key-Pins Header is Set and gives you actionable findings to investigate.
Start a free scanRelated Issues
- X-XSS-Protection Header is Set - Vulnerability
- Cookie without Secure Flag - Vulnerability
- Strict-Transport-Security Header is Missing - Vulnerability
- Session Cookie without Secure Flag - Vulnerability


