XFO also might be useful if the blog has predictable layout of the admin interface — logged-in blog admin could be tricked via clickjacking to perform potentially undesirable actions.
Edit: As others pointed it out, it's a Drupal installation. Trusting Drupal to be 100% safe in regards to malicious attacks is not a good idea. I know this is nitpicking, it is however still ironic.
http://www.cvedetails.com/vulnerability-list/vendor_id-1367/...
His HTTPS endpoint is not trusted by the browser, either self-signed or missing some intermediary cert... If he wants to enable the contact form for business inquiry or personal inquiry, might be worthwhile to get some $10 cert? If he already ahve gotten that far to get a 443 port enabled.
XCTO is pretty cheap to enable and doesn't hurt. The only problem is IRRC IE has a different MIME list then Firefox and Chrome.
It's pretty cheap to enable some of these security headers, just as it is relatively easy to disable some of the server-type headers (x-powered-by e.g, which apparently he doesn't have it exposed I think)