30 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31536000
Content-Security-Policy
Basic
report-uri; default-src; img-src; +10 more Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Improve CSP by adding more specific directives and removing 'unsafe-inline'
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

Performance Headers

Connection
Performance
close
Vary
Performance
Accept-Language

Caching Headers

Cache-Control
Caching
private, no-cache, no-store, must-revalidate
Expires
Caching
Sat, 01 Jan 2000 00:00:00 GMT
Pragma
Caching
no-cache

Content Headers

Content-Length
Content
20928
Content-Type
Content
text/html; charset=utf-8

Server Headers

No server headers found

CORS Headers

No CORS headers found

Cookies Headers

Set-Cookie
Cookies

Other Headers

Alt-Svc
Other
h3=":443"; ma=86400
Cross-Origin-Embedder-Policy-Report-Only
Other
require-corp;report-to="coep"
Date
Other
Mon, 23 Feb 2026 09:33:24 GMT
Proxy-Status
Other
http_request_error; e_fb_vipaddr="AcNLhzuwbIsAYhUfUUl41NYh5Cc8t3RZiJyeI4jiYr70Agl6H6WWXI2Q-Bnx-9br_pNgKlLLtRh0jS2PVAYGVGonAksFT45HLtO-8VA"; e_clientaddr="AcMLhahNeLtHlYmANwW5rYsCI_I6PL4z4oEm4LSrae7xFXOgpxdROzNy2At7p0MUVU2XRuCJF2WdVxJQKBlTjHW2cAx3eKjLuLI0Hdm0wzZR3yeRHg"; e_upip="AcOCz2OtMH_67p0Tcw7rE9w8YKgEmy0TqiZEXWTcZtPyzOVpRZdEID6cES-PaHbvhNT7H2ek24s4-DRNHdS5C5NA72qOsxvUIOU"; e_fb_zone="AcPOa9p0VDyx3CkxiqZtQ2hAA8lpCa8gSTt1nPRu9GTUXKy5zDcro949h8Y9KFQR"; e_fb_twtaskhandle="AcMANp18DpMmdLxAopgmzjW-YRfDreB3X5mDMgwvnZACkDhXTYjSgd3B4IRJj_jWmmE4TMAqkgDmUmdqyCd8Bcmv7kC-7QU6c2Y6028y"; e_proxy="AcNN75M_TfJ_9c-jk4-qXDjz4ggGxRrm2FzwWj6hW4I6GYS40-lK9boQEPb3GcEhzrroK4r1GREogRDBnzHX", http_request_error; e_fb_vipaddr="AcOAmLgxZ8MSNU80qdUjhcuFO5K2ltmc2WltFqRt1cXBhgerxBtevqo4kU8r4RYYyzSRTdweLyY"; e_clientaddr="AcPutTH0yotAzix6IeWrnzpoM-mjpmYH1phPHkFfKqUf2Md-h3Q4yZE1bCk-gNKm41CmNE3i4yCEeS2scQ"; e_upip="AcMPrByhL-X5R7-v1p6iQMyjEY5aKDpcdLRsEkoydzDdq_duqxF2bWVFU_QvSF3if3hepYqoB-DFr1I4GvoWr91r48jivw_fl5-wRTI"; e_fb_zone="AcM3SQf75AbHAuGsHW55FNlMxCHe-jVj2AmGdKFjRzw9dWwyd2n2iimhVhoAnQ"; e_fb_twtaskhandle="AcO0stT9c2EZ3fzsf_NqMkNDfrN5uwixMaYwJ3H46_gVydR6Iy6ykL7q1k3YGBUK0u2wLfpiLc-QboHLbmeD_JV1nm1pEBQsUZxy"; e_proxy="AcOJhJXqkDXEqKFGL_WW8VlmPw2z_L-Gm-TbORIGE9b5dC_MDwzIvAZn3oCljpg43doLQE3LEPdx8sA"
Report-To
Other
{"group": "coep", "max_age": 86400, "endpoints": [{"url": "/security/coep_report/"}]},{"group": "coop", "max_age": 86400, "endpoints": [{"url": "/security/coop_report/"}]}
X-Aed
Other
751
X-Fb-Connection-Quality
Other
EXCELLENT; q=0.9, rtt=15, rtx=0, c=13, mss=1368, tbw=3206, tp=-1, tpl=-1, uplat=93, ullat=0
X-Ig-Cache-Control
Other
no-cache
X-Ig-Capacity-Level
Other
3
X-Ig-Origin-Region
Other
frc
X-Ig-Peak-Time
Other
1
X-Ig-Peak-V2
Other
0
X-Ig-Push-State
Other
c2
X-Ig-Request-Elapsed-Time-Ms
Other
85
X-Perf-Stats
Other
0;0;0
X-Stack
Other
distillery

Recommendations

Enable compression (gzip/brotli) to improve performance