12 Headers

Detected Technologies from Headers

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Present
same-origin
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Consider adding Permissions-Policy to control browser features

Performance Headers

Connection
Performance
close
Vary
Performance
Accept, Cookie, origin

Caching Headers

No caching headers found

Content Headers

Content-Length
Content
125
Content-Type
Content
application/json

Server Headers

Server
Server
Google Frontend

CORS Headers

No CORS headers found

Cookies Headers

No cookies headers found

Other Headers

Allow
Other
GET, HEAD, OPTIONS
Date
Other
Tue, 12 May 2026 13:45:32 GMT
X-Cloud-Trace-Context
Other
184569d05a76c532a6f4721cda82af45;o=1

Recommendations

Enable compression (gzip/brotli) to improve performance

Add Cache-Control header to optimize caching