Security Headers and Google Analytics Fixes
Budget: ₹1,500 – ₹12,500 INR
Project Brief: Website Security Header Fixes + GA4 Data Issue Resolution for SabPaisa.in
Background
We recently completed a web application penetration test on sabpaisa.in conducted by Indian Cyber Security Solutions. The assessment identified three low-severity vulnerabilities related to HTTP security headers, all currently open and requiring remediation. Additionally, we are experiencing a data discrepancy issue in Google Analytics 4 (GA4) that needs investigation and fixing.
Part 1 – Security Header Fixes (Pentest Findings)
We need a developer experienced in web server configuration (Hostinger VPS) and/or Cloudflare/CDN settings to address the following three findings:
Finding 1 – Duplicate Security Headers Misconfiguration (CVSS 2.6)
Headers like X-Frame-Options, X-Content-Type-Options, and X-XSS-Protection are being sent multiple times in the HTTP response. The fix requires consolidating these headers across all layers — web server, PHP backend, and CDN — so each header appears exactly once.
Finding 2 – Information Disclosure via Headers (CVSS 2.6)
The server is exposing backend technology details through custom headers (X-Flying-Press-Source: PHP, X-Flying-Press-Cache: HIT). These need to be suppressed or removed at the server/CDN configuration level to prevent technology fingerprinting.
Finding 3 – Missing Security Headers (CVSS 2.5)
The following critical headers are absent from HTTP responses and need to be properly implemented:
Content-Security-Policy (CSP)
Permissions-Policy
Cross-Origin-Embedder-Policy (COEP)
Cross-Origin-Resource-Policy (CORP)
Cross-Origin-Opener-Policy (COOP)
All 12+ pages within scope (sabpaisa.in and subpages) must be covered. After fixes are applied, we will verify using Burp Suite and header scanning tools.
Deliverable: Updated server/CDN configuration files with documented changes, and confirmation screenshots showing clean header responses.
Part 2 – GA4 Misconfiguration / Data Issue
We are seeing data discrepancies in our Google Analytics 4 property for sabpaisa.in. We need someone experienced in GA4 auditing and debugging to investigate and resolve the issue.
Specifically, we want:
A full audit of the current GA4 setup (tag implementation, data streams, filters)
Identification of any misconfigured events, duplicate triggers, or missing conversions
Investigation of any self-referral traffic or bot/spam inflation
Cross-referencing GA4 data with Google Tag Manager (GTM) if applicable
A clean, corrected configuration with documentation of what was changed and why
Deliverable: Written audit findings, corrected GA4/GTM configuration, and a brief explanation of the root cause.
Tech Stack / Environment
Website: sabpaisa.in (WordPress/PHP-based, behind Cloudflare CDN)
Server: Hostinger VPS
Analytics: Google Analytics 4 + Google Tag Manager
Budget & Timeline
Open to quotes. Please share relevant experience with pentest remediation and GA4 auditing when applying.
Background
We recently completed a web application penetration test on sabpaisa.in conducted by Indian Cyber Security Solutions. The assessment identified three low-severity vulnerabilities related to HTTP security headers, all currently open and requiring remediation. Additionally, we are experiencing a data discrepancy issue in Google Analytics 4 (GA4) that needs investigation and fixing.
Part 1 – Security Header Fixes (Pentest Findings)
We need a developer experienced in web server configuration (Hostinger VPS) and/or Cloudflare/CDN settings to address the following three findings:
Finding 1 – Duplicate Security Headers Misconfiguration (CVSS 2.6)
Headers like X-Frame-Options, X-Content-Type-Options, and X-XSS-Protection are being sent multiple times in the HTTP response. The fix requires consolidating these headers across all layers — web server, PHP backend, and CDN — so each header appears exactly once.
Finding 2 – Information Disclosure via Headers (CVSS 2.6)
The server is exposing backend technology details through custom headers (X-Flying-Press-Source: PHP, X-Flying-Press-Cache: HIT). These need to be suppressed or removed at the server/CDN configuration level to prevent technology fingerprinting.
Finding 3 – Missing Security Headers (CVSS 2.5)
The following critical headers are absent from HTTP responses and need to be properly implemented:
Content-Security-Policy (CSP)
Permissions-Policy
Cross-Origin-Embedder-Policy (COEP)
Cross-Origin-Resource-Policy (CORP)
Cross-Origin-Opener-Policy (COOP)
All 12+ pages within scope (sabpaisa.in and subpages) must be covered. After fixes are applied, we will verify using Burp Suite and header scanning tools.
Deliverable: Updated server/CDN configuration files with documented changes, and confirmation screenshots showing clean header responses.
Part 2 – GA4 Misconfiguration / Data Issue
We are seeing data discrepancies in our Google Analytics 4 property for sabpaisa.in. We need someone experienced in GA4 auditing and debugging to investigate and resolve the issue.
Specifically, we want:
A full audit of the current GA4 setup (tag implementation, data streams, filters)
Identification of any misconfigured events, duplicate triggers, or missing conversions
Investigation of any self-referral traffic or bot/spam inflation
Cross-referencing GA4 data with Google Tag Manager (GTM) if applicable
A clean, corrected configuration with documentation of what was changed and why
Deliverable: Written audit findings, corrected GA4/GTM configuration, and a brief explanation of the root cause.
Tech Stack / Environment
Website: sabpaisa.in (WordPress/PHP-based, behind Cloudflare CDN)
Server: Hostinger VPS
Analytics: Google Analytics 4 + Google Tag Manager
Budget & Timeline
Open to quotes. Please share relevant experience with pentest remediation and GA4 auditing when applying.
Related categories:
PHP
Web Security
WordPress
Apache
Google Analytics
Nginx
Internet Security
Penetration Testing
Data Analysis
Cloudflare