19 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains
Content-Security-Policy
Basic
default-src; worker-src; report-uri
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Missing
Not configured
Recommendations
  • Consider adding 'preload' to HSTS for maximum security
  • Improve CSP by adding more specific directives and removing 'unsafe-inline'
  • Consider adding Permissions-Policy to control browser features

Performance Headers

1 headers
Connection
Performance
close

Caching Headers

3 headers
Cache-Control
Caching
no-store
Expires
Caching
-1
Pragma
Caching
no-cache

Content Headers

2 headers
Content-Length
Content
3627
Content-Type
Content
text/html; charset=utf-8

Server Headers

1 headers
Server
Server
phrase.com

CORS Headers

0 headers
No CORS headers found

Cookies Headers

1 headers
Set-Cookie
Cookies
_phrase_session_sec=ZGoJ0VhiMk1N2W1LVvB6arGmuXy88tGsWVsVrpGqpcLNEFkkulc%2Blzk6p7yZv9Ec6EQndZSrpmV%2BRxAWgH2exZD%2BlCa1uaxNhVPoxalOkLxHGQX6nrwy4UQmdoU9QKAg6ykD4WUFUOFJ693KqHXKMOGI4od%2B%2Fjgwd%2FodcrPVdL%2BWFmEZ615TcVmi8KQTg2aqZsctoCYMA73%2F1PKZxY68A%2FQjZe79L85oYn5%2FWens3Lk%2BU2mjbrr6ySKMajLJzqfKe9aA1N6RcRNbfiaFxs9TEbN%2FqzOns%2Bv9W3XuyOLCr5g5xfIRWDQBJfe7qPjyS7MokQ%3D%3D--i6Vac7z2a%2BprGkl6--asVzGsaUYVOB%2BHHtSYnQTw%3D%3D; path=/; expires=Thu, 29 Jan 2026 20:40:15 GMT; secure; HttpOnly; SameSite=Lax

Other Headers

5 headers
Date
Other
Tue, 30 Dec 2025 20:40:15 GMT
Link
Other
<https://d20j2y33fgycdj.cloudfront.net/assets/error-fb4270277382ba863e36e7d7fb69e74b001106164e3a3d35cd30d755011d30ed.css>; rel=preload; as=style; nopush
X-Generated
Other
2025-12-30T20:40:15+00:00
X-Permitted-Cross-Domain-Policies
Other
none
X-Robots-Tag
Other
noindex

Recommendations

Enable compression (gzip/brotli) to improve performance