Protect your blog with additional fetures in the HTTP response header
Important note: HTTPS should have been mandatory long ago!
The CSP guidelines enforce the use of HTTPS. We therefore recommend that you encrypt the HTTP data stream. To do this, the web server requires an SSL certificate. These are usually subject to a fee, but since Mozilla launched the "Let's encrypt!" initiative, such certificates are also available free of charge, depending on the hosting partner.
Here you can check the security of your Flatpress blog https://securityheaders.com/