20 Headers

Detected Technologies from Headers

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Present
camera=(), microphone=(), geolocation=()
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking

Performance Headers

Connection
Performance
close
Vary
Performance
Origin

Caching Headers

No caching headers found

Content Headers

Content-Length
Content
16
Content-Type
Content
application/json

Server Headers

Server
Server
Google Frontend

CORS Headers

No CORS headers found

Cookies Headers

No cookies headers found

Other Headers

Accept-Encoding
Other
gzip, deflate
Date
Other
Sun, 10 May 2026 01:20:54 GMT
Ratelimit-Limit
Other
100
Ratelimit-Remaining
Other
99
Ratelimit-Reset
Other
1
Traceparent
Other
00-d88f27789ae5ab1306f9adf63c2d4989-b5cba49216ce6f7d-01
Tracestate
Other
newrelic=d88f27789ae5ab1306f9adf63c2d4989
X-Cloud-Trace-Context
Other
b9cdcfae180f6421c21e72f7e6636432;o=1
X-Rate-Limit-Duration
Other
1
X-Rate-Limit-Limit
Other
100.00
X-Rate-Limit-Request-Forwarded-For
Other
216.246.40.71
X-Rate-Limit-Request-Remote-Addr
Other
169.254.169.126:17330

Recommendations

Enable compression (gzip/brotli) to improve performance

Add Cache-Control header to optimize caching