Open
Cached
·
just now
14
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=15724800; includeSubDomains
Content-Security-Policy
Strong
font-src; script-src; style-src; +8 more
font-src *; script-src 'self' https://maps.google.com https://accounts.google.com https://www.google-analytics.com 'sha256-SxNB1/NQ1TUHWrwTi7scFI31VsahWQBj54W7KQZQs1Q=' 'sha256-isH538cVBUY8IMlGYGbWtBwr+cGqkc4mN6nLcA7lUjE=' 'sha256-3N2Z+Nu++/yNMVHIl863JigVmt2Nr9gt2doEMJT2Wzk='; style-src 'self' 'nonce-pBQKIFT9wO' https://accounts.google.com; manifest-src 'self'; connect-src 'self' https://accounts.google.com metabase.us10.list-manage.com https://sp.metabase.com ; img-src * 'self' data:; frame-src 'self' https://www.metabase.com/ https://metabase.com/ youtube.com *.youtube.com youtu.be *.youtu.be loom.com *.loom.com vimeo.com *.vimeo.com docs.google.com calendar.google.com airtable.com *.airtable.com typeform.com *.typeform.com canva.com *.canva.com codepen.io *.codepen.io figma.com *.figma.com grafana.com *.grafana.com miro.com *.miro.com excalidraw.com *.excalidraw.com notion.com *.notion.com atlassian.com *.atlassian.com trello.com *.trello.com asana.com *.asana.com gist.github.com linkedin.com *.linkedin.com twitter.com *.twitter.com x.com *.x.com; default-src 'none'; media-src www.metabase.com; child-src 'self' https://accounts.google.com; frame-ancestors 'none';
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
2 headers
Connection
Performance
close
Transfer-Encoding
Performance
chunked
Caching Headers
3 headers
Cache-Control
Caching
max-age=0, no-cache, must-revalidate, proxy-revalidate
Expires
Caching
Tue, 03 Jul 2001 06:00:00 GMT
Last-Modified
Caching
Wed, 31 Dec 2025 19:51:25 GMT
Content Headers
1 headers
Content-Type
Content
text/html;charset=utf-8
Server Headers
0 headers
No server headers found
CORS Headers
0 headers
No CORS headers found
Cookies Headers
1 headers
Set-Cookie
Cookies
metabase.DEVICE=4f36a5d8-86aa-41b0-9bdb-63530c5e3360; HttpOnly; Path=/; Expires=Sun, 31 Dec 2045 19:51:25 GMT; SameSite=None; Secure
Other Headers
2 headers
Date
Other
Wed, 31 Dec 2025 19:51:25 GMT
X-Permitted-Cross-Domain-Policies
Other
none
Recommendations
Enable compression (gzip/brotli) to improve performance