Open
Cached
·
just now
18
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Excellent
max-age=63072000; includeSubDomains; preload
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
2 headers
Accept-Ranges
Performance
bytes
Connection
Performance
close
Caching Headers
3 headers
Cache-Control
Caching
max-age=0
Etag
Caching
"8944e39af5f404a2f0634790d3a0b299"
Last-Modified
Caching
Sat, 10 Jan 2026 08:55:13 GMT
Content Headers
2 headers
Content-Length
Content
5007
Content-Type
Content
text/html
Server Headers
1 headers
Server
Server
AmazonS3
CORS Headers
0 headers
No CORS headers found
Cookies Headers
0 headers
No cookies headers found
Other Headers
7 headers
Content-Security-Policy-Report-Only
Other
worker-src blob:; object-src https://backend-exportsbucket-gdohx8yidefz.s3.eu-central-1.amazonaws.com/ https://backend-exportstemplatebucket-redgyjyc4d38.s3.eu-central-1.amazonaws.com/ https://backend-attachmentsbucket-ce8o0flxzb3b.s3.eu-central-1.amazonaws.com/ https://backend-organisationlogobucket-170pjy03djf34.s3.eu-central-1.amazonaws.com/; script-src 'self' 'unsafe-eval' https://maps.googleapis.com https://fast.appcues.com/95174.js https://fast.appcues.com/generic/main/; script-src-attr 'unsafe-inline'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com/ https://cdnjs.cloudflare.com/ https://use.fontawesome.com https://fast.appcues.com/generic/main/; style-src-attr 'unsafe-inline'; base-uri 'self';; report-uri https://csp-report.browser-intake-datadoghq.eu/api/v2/logs?dd-api-key=pubd9fd9982e20053f793ee8d92705898c1&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=service%3Awebapp%2Cenv%3Aproduction%2Cversion%3A0.1.22
Date
Other
Mon, 12 Jan 2026 08:01:00 GMT
Via
Other
1.1 f958a7ff273f1fbe2d4c89cc6e059db8.cloudfront.net (CloudFront)
X-Amz-Cf-Id
Other
v4a1LYfijkM6n2QilA28P6fj22HhXDb_vswM7eZsvCIWgRhsDTh0yA==
X-Amz-Cf-Pop
Other
IAD61-P11
X-Amz-Server-Side-Encryption
Other
AES256
X-Cache
Other
Miss from cloudfront
Recommendations
Enable compression (gzip/brotli) to improve performance