HTTP Security Headers

Status
Strict-Transport-Security
Good
max-age=63072000; includeSubDomains
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Present
ALLOWALL
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Consider adding 'preload' to HSTS for maximum security
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

Performance Headers

1 headers
Connection
Performance
keep-alive

Caching Headers

4 headers
Cache-Control
Caching
public, max-age=300
Etag
Caching
c256db03-1b67-4a18-afdd-722f3db79528
Expires
Caching
Thu, 13 Nov 2025 11:31:38 GMT
Last-Modified
Caching
Thu, 31 Jul 2025 10:25:55 GMT

Content Headers

3 headers
Content-Length
Content
3597
Content-Md5
Content
ffnQGAvDu6EdwmSXZ85cfg==
Content-Type
Content
text/html;charset=utf-8

Server Headers

0 headers
No server headers found

CORS Headers

1 headers
Access-Control-Allow-Origin
Cors
*

Cookies Headers

0 headers
No cookies headers found

Other Headers

8 headers
Ak-Grn
Other
0.2c4e4e68.1763033197.87dc7110
Akamai-Request-Bc
Other
[a=104.78.78.44,b=2279371024,c=g,n=US_VA_STERLING,o=20940]
Date
Other
Thu, 13 Nov 2025 11:26:38 GMT
Opc-Request-Id
Other
oci-601781475936746-202510290233/E4062AADC8EF4371F57C0169444C4E69/A92345AA2BFA9106D54F747D07FD7BB9
X-Cache
Other
TCP_REFRESH_HIT from a104-78-78-44.deploy.akamaitechnologies.com (AkamaiGHost/22.3.1-cc61a4af8cfe783fae677e7a432c89ef) (S)
X-Cache-Key
Other
S/L/130756/1664632/2h/activate-oc35.cloud.oracle.com/
X-Cache-Remote
Other
TCP_REFRESH_MISS from a23-218-223-12.deploy.akamaitechnologies.com (AkamaiGHost/22.3.1-cc61a4af8cfe783fae677e7a432c89ef) (S)
X-True-Cache-Key
Other
/L/activate-oc35.cloud.oracle.com/ vcd=10647

Recommendations

Enable compression (gzip/brotli) to improve performance

Analysis completed in 1852ms