Open
Cached
·
just now
35
Headers
Detected Technologies from Headers
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=15552000; includeSubDomains
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
no-referrer
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Strengthen CSP by removing 'unsafe-eval'
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
Transfer-Encoding
chunked
Vary
Accept-Encoding, Accept-Encoding
connection: close transfer-encoding: chunked vary: Accept-Encoding, Accept-Encoding
Caching Headers
Etag
W/"70-QiCuFrNhoJZFbNQq6ZXc79vceag"
etag: W/"70-QiCuFrNhoJZFbNQq6ZXc79vceag"
Content Headers
Content-Type
application/json; charset=utf-8
content-type: application/json; charset=utf-8
CORS Headers
Access-Control-Allow-Headers
Accept, Accept-Language, Authorization, Baggage, Content-Language, Content-Type, Sentry-Trace, Traceparent, Tracestate, User-Agent, X-Forwarded-For, X-Forwarded-Host, X-Forwarded-Proto, X-Real-IP, X-Request-Id, X-Requested-With, X-Trm-Referrer, X-Trm-Request-Trace
Access-Control-Allow-Methods
GET, POST, PATCH, PUT, DELETE, OPTIONS
Access-Control-Allow-Origin
*
Access-Control-Expose-Headers
LF-Trace-Id, Trace-Id, x-trm-co-case-session-uuid
access-control-allow-headers: Accept, Accept-Language, Authorization, Baggage, Content-Language, Content-Type, Sentry-Trace, Traceparent, Tracestate, User-Agent, X-Forwarded-For, X-Forwarded-Host, X-Forwarded-Proto, X-Real-IP, X-Request-Id, X-Requested-With, X-Trm-Referrer, X-Trm-Request-Trace access-control-allow-methods: GET, POST, PATCH, PUT, DELETE, OPTIONS access-control-allow-origin: * access-control-expose-headers: LF-Trace-Id, Trace-Id, x-trm-co-case-session-uuid
Cookies Headers
Other Headers
Alt-Svc
h3=":443"; ma=86400
Date
Tue, 12 May 2026 04:02:13 GMT
Feature-Policy
ambient-light-sensor 'none'; autoplay 'none'; battery 'none'; camera 'none'; display-capture 'none'; document-domain 'none'; encrypted-media 'none'; execution-while-not-rendered 'none'; execution-while-out-of-viewport 'none'; fullscreen 'none'; geolocation 'none'; gyroscope 'none'; layout-animations 'none'; legacy-image-formats 'none'; magnetometer 'none'; microphone 'none'; midi 'none'; navigation-override 'none'; oversized-images 'none'; payment 'none'; picture-in-picture 'none'; publickey-credentials-get 'none'; screen-wake-lock 'none'; sync-xhr 'none'; usb 'none'; vr 'none'; wake-lock 'none'; web-share 'none'; xr-spatial-tracking 'none';
Server-Timing
cfCacheStatus;desc="DYNAMIC", cfEdge;dur=17,cfOrigin;dur=46
Trace-Id
994d052d6ec4a2824a06ad7f68a2c881
Trace-Parent-Id
11c0f39f774787e8
Trace-Sampled
true
X-Dns-Prefetch-Control
off
X-Download-Options
noopen
X-Permitted-Cross-Domain-Policies
none
X-Ratelimit-Limit
100000
X-Ratelimit-Remaining
99999
X-Ratelimit-Reset
1778644934
X-Render-Origin-Server
nginx
alt-svc: h3=":443"; ma=86400 cf-cache-status: DYNAMIC cf-ray: 9fa686d30a6dc99b-IAD date: Tue, 12 May 2026 04:02:13 GMT feature-policy: ambient-light-sensor 'none'; autoplay 'none'; battery 'none'; camera 'none'; display-capture 'none'; document-domain 'none'; encrypted-media 'none'; execution-while-not-rendered 'none'; execution-while-out-of-viewport 'none'; fullscreen 'none'; geolocation 'none'; gyroscope 'none'; layout-animations 'none'; legacy-image-formats 'none'; magnetometer 'none'; microphone 'none'; midi 'none'; navigation-override 'none'; oversized-images 'none'; payment 'none'; picture-in-picture 'none'; publickey-credentials-get 'none'; screen-wake-lock 'none'; sync-xhr 'none'; usb 'none'; vr 'none'; wake-lock 'none'; web-share 'none'; xr-spatial-tracking 'none'; rndr-id: 2bb2c519-4830-4738 server-timing: cfCacheStatus;desc="DYNAMIC", cfEdge;dur=17,cfOrigin;dur=46 trace-id: 994d052d6ec4a2824a06ad7f68a2c881 trace-parent-id: 11c0f39f774787e8 trace-sampled: true x-dns-prefetch-control: off x-download-options: noopen x-permitted-cross-domain-policies: none x-ratelimit-limit: 100000 x-ratelimit-remaining: 99999 x-ratelimit-reset: 1778644934 x-render-origin-server: nginx
Recommendations
Enable compression (gzip/brotli) to improve performance
Add Cache-Control header to optimize caching