22 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31536000
Content-Security-Policy
Weak
connect-src-src
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Significantly strengthen CSP directives
  • Consider adding Permissions-Policy to control browser features

Performance Headers

1 headers
Connection
Performance
close

Caching Headers

1 headers
Etag
Caching
W/"1f-favkM3gKsz2tJep2BvvNc6R+ouI"

Content Headers

2 headers
Content-Length
Content
31
Content-Type
Content
application/json; charset=utf-8

Server Headers

1 headers
X-Powered-By
Server
Express

CORS Headers

3 headers
Access-Control-Allow-Credentials
Cors
true
Access-Control-Allow-Headers
Cors
X-Requested-With, X-HTTP-Method-Override, X-Beam-Client, X-Beam-Client-Version, Content-Type, Accept, Authorization
Access-Control-Allow-Origin
Cors
*

Cookies Headers

0 headers
No cookies headers found

Other Headers

8 headers
Alt-Svc
Other
h3=":443"; ma=86400
Date
Other
Thu, 25 Dec 2025 10:24:23 GMT
Via
Other
1.1 65e185f36e65abff9322e261be3491d4.cloudfront.net (CloudFront)
X-Amz-Cf-Id
Other
P9JYF6NYwrZgACRt3cX23go9YD4NqqdDC7d3cJWY7WqHAj8zJeIDoQ==
X-Amz-Cf-Pop
Other
IAD50-C2
X-Cache
Other
Error from cloudfront
X-Chain-Id
Other
null
X-Request-Id
Other
b4999f36-2b26-47ff-bc91-9c39c58c76c8

Recommendations

Enable compression (gzip/brotli) to improve performance

Add Cache-Control header to optimize caching

Consider removing X-Powered-By header to hide server technology

Analysis completed in 181ms