Cached · just now
15 Headers

Detected Technologies from Headers

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=15552000; includeSubDomains; preload
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Present
same-origin
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Consider adding Permissions-Policy to control browser features

Performance Headers

Connection
Performance
close
Vary
Performance
accept-encoding

Caching Headers

No caching headers found

Content Headers

No content headers found

Server Headers

Server
Server
cloudflare

CORS Headers

No CORS headers found

Cookies Headers

No cookies headers found

Other Headers

Alt-Svc
Other
h3=":443"; ma=86400
Cf-Ray
Other
9f5ff42db9013943-IAD
Date
Other
Sun, 03 May 2026 14:28:43 GMT
Link
Other
Server-Timing
Other
cfEdge;dur=21,cfOrigin;dur=0,cfWorker;dur=0
Speculation-Rules
Other
"/cdn-cgi/speculation"

Recommendations

Enable compression (gzip/brotli) to improve performance

Add Cache-Control header to optimize caching