Open
Cached
·
just now
14
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
no-referrer
Permissions-Policy
Present
accelerometer=(), camera=(), geolocation=(); +4 more
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
Performance Headers
Connection
close
Vary
Origin
connection: close vary: Origin
Caching Headers
Cache-Control
no-store
cache-control: no-store
Content Headers
Content-Length
258
Content-Type
application/json
content-length: 258 content-type: application/json
Server Headers
Server
Ktor/3.4.2
server: Ktor/3.4.2
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Alt-Svc
h3=":443"; ma=2592000
Date
Sat, 05 Sep 2026 15:38:09 GMT
Server-Timing
app;dur=12.5
X-Request-Id
b48208cf-7699-402e-ad68-3e18778fd84c
alt-svc: h3=":443"; ma=2592000 date: Sat, 05 Sep 2026 15:38:09 GMT server-timing: app;dur=12.5 x-request-id: b48208cf-7699-402e-ad68-3e18778fd84c
Recommendations
Enable compression (gzip/brotli) to improve performance