What it is
Checks the response headers that harden a site against browser-side attacks. HSTS forces HTTPS. Content-Security-Policy restricts where scripts, styles and other resources may load from, and is the main defence against cross-site scripting. X-Content-Type-Options stops browsers second-guessing a declared content type. X-Frame-Options controls whether the page can be embedded in a frame, which is what prevents clickjacking.
Why it matters
These cost nothing to add and are very often simply absent. A site missing all of them is not necessarily exploitable, but it has opted out of several protections the browser would otherwise enforce on its behalf.