At the moment only the `Content-Type` Header gets also checked via `meta` tag. We should enable to scan also the meta tags set on the HTML itself, although it might not be as secure as the HTTP-Header.