The recent check performed by The Mozilla Observatory shows that https://eshop.totaljs.com/ has a low score with an F grade due to the implementation of the required headers.

A Helmet.js integration can be performed as an option.

It shows an A+ grade then, but the website becomes unusable and produces many errors after this integration (mostly because of using 'unsafe-eval' and 'unsafe-inline').