Open
Cached
·
just now
22
Headers
Detected Technologies from Headers
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=631138519; includeSubdomains
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
Transfer-Encoding
chunked
Vary
accept-encoding
connection: close transfer-encoding: chunked vary: accept-encoding
Caching Headers
Cache-Control
no-cache, no-store, max-age=0
cache-control: no-cache, no-store, max-age=0
Content Headers
Content-Disposition
attachment; filename=json.json
Content-Type
application/json;charset=utf-8
content-disposition: attachment; filename=json.json content-type: application/json;charset=utf-8
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Date
Sun, 23 Aug 2026 21:53:04 GMT
Origin-Cf-Ray
a2fd59146e4a241c-ATL
Perf
7402827104
Timing-Allow-Origin
https://x.com, https://mobile.x.com
X-Response-Time
80
X-Served-By
t4_a
X-Transaction
1c29f38814ae5d1e
X-Transaction-Id
1c29f38814ae5d1e
cf-cache-status: DYNAMIC cf-ray: a2fd59146e4a241c-IAD date: Sun, 23 Aug 2026 21:53:04 GMT origin-cf-ray: a2fd59146e4a241c-ATL perf: 7402827104 timing-allow-origin: https://x.com, https://mobile.x.com x-response-time: 80 x-served-by: t4_a x-transaction: 1c29f38814ae5d1e x-transaction-id: 1c29f38814ae5d1e
Recommendations
Enable compression (gzip/brotli) to improve performance