Cached · just now
35 Headers

Detected Technologies from Headers

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=15552000; includeSubDomains
Content-Security-Policy
Good
default-src; base-uri; block-all-mixed-content; +8 more Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
no-referrer
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Strengthen CSP by removing 'unsafe-eval'
  • Consider adding Permissions-Policy to control browser features

Performance Headers

Connection
Performance
close
Transfer-Encoding
Performance
chunked
Vary
Performance
Accept-Encoding, Accept-Encoding

Caching Headers

Etag
Caching
W/"70-QiCuFrNhoJZFbNQq6ZXc79vceag"

Content Headers

Content-Type
Content
application/json; charset=utf-8

Server Headers

Server
Server
cloudflare

CORS Headers

Access-Control-Allow-Headers
Cors
Accept, Accept-Language, Authorization, Baggage, Content-Language, Content-Type, Sentry-Trace, Traceparent, Tracestate, User-Agent, X-Forwarded-For, X-Forwarded-Host, X-Forwarded-Proto, X-Real-IP, X-Request-Id, X-Requested-With, X-Trm-Referrer, X-Trm-Request-Trace
Access-Control-Allow-Methods
Cors
GET, POST, PATCH, PUT, DELETE, OPTIONS
Access-Control-Allow-Origin
Cors
*
Access-Control-Expose-Headers
Cors
LF-Trace-Id, Trace-Id, x-trm-co-case-session-uuid

Cookies Headers

Set-Cookie
Cookies

Other Headers

Alt-Svc
Other
h3=":443"; ma=86400
Cf-Cache-Status
Other
DYNAMIC
Cf-Ray
Other
9fa686d30a6dc99b-IAD
Date
Other
Tue, 12 May 2026 04:02:13 GMT
Feature-Policy
Other
ambient-light-sensor 'none'; autoplay 'none'; battery 'none'; camera 'none'; display-capture 'none'; document-domain 'none'; encrypted-media 'none'; execution-while-not-rendered 'none'; execution-while-out-of-viewport 'none'; fullscreen 'none'; geolocation 'none'; gyroscope 'none'; layout-animations 'none'; legacy-image-formats 'none'; magnetometer 'none'; microphone 'none'; midi 'none'; navigation-override 'none'; oversized-images 'none'; payment 'none'; picture-in-picture 'none'; publickey-credentials-get 'none'; screen-wake-lock 'none'; sync-xhr 'none'; usb 'none'; vr 'none'; wake-lock 'none'; web-share 'none'; xr-spatial-tracking 'none';
Rndr-Id
Other
2bb2c519-4830-4738
Server-Timing
Other
cfCacheStatus;desc="DYNAMIC", cfEdge;dur=17,cfOrigin;dur=46
Trace-Id
Other
994d052d6ec4a2824a06ad7f68a2c881
Trace-Parent-Id
Other
11c0f39f774787e8
Trace-Sampled
Other
true
X-Dns-Prefetch-Control
Other
off
X-Download-Options
Other
noopen
X-Permitted-Cross-Domain-Policies
Other
none
X-Ratelimit-Limit
Other
100000
X-Ratelimit-Remaining
Other
99999
X-Ratelimit-Reset
Other
1778644934
X-Render-Origin-Server
Other
nginx

Recommendations

Enable compression (gzip/brotli) to improve performance

Add Cache-Control header to optimize caching