Using a web application spanning over tens of hosts with even more URLs it's hard to tell where exactly security headers are missing -- using Burp and existing plugins.
Reading the docs here a plugin shouldn't be far away and it would be of much help in this and other cases.