Open
Cached
·
just now
28
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=63072000; includeSubdomains;
Content-Security-Policy
Weak
frame-ancestors
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Good
no-referrer-when-downgrade
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Significantly strengthen CSP directives
- • Add X-Content-Type-Options: nosniff
- • Consider adding Permissions-Policy to control browser features
Performance Headers
3 headers
Connection
Performance
Upgrade
Transfer-Encoding
Performance
chunked
Vary
Performance
Accept-Encoding
Caching Headers
2 headers
Cache-Control
Caching
max-age=0
Expires
Caching
Tue, 11 Nov 2025 14:20:34 GMT
Content Headers
1 headers
Content-Type
Content
text/html; charset=UTF-8
Server Headers
1 headers
Server
Server
Apache
CORS Headers
0 headers
No CORS headers found
Cookies Headers
1 headers
Set-Cookie
Cookies
fbtoken=zuq; Secure; path=/; SameSite=Lax; Max-Age=31536000; Expires=Wednesday, 11-Nov-2026 14:20:34 UTC
Other Headers
15 headers
Date
Other
Tue, 11 Nov 2025 14:20:34 GMT
Feature-Policy
Other
camera 'none'; microphone 'none'; geolocation 'none';
Link
Other
</src/js/post/emvepe.generated.js?v=dbee141d9e84c7e83cb5c49d25a29ac5>; rel=preload; as=script, </src/js/lib/firebase.remote.js>; rel=preload; as=script, </src/css/emvepe.min.css?v=dbee141d9e84c7e83cb5c49d25a29ac5>; rel=preload; as=style, <https://firebaseinstallations.googleapis.com>; rel=preconnect;, <https://www.googletagmanager.com>; rel=preconnect;, </assets/fonts/SharpSansDispNo1-Medium.woff2>; rel=preload; as=font; type=font/woff2; crossorigin=anonymous;, </assets/fonts/SharpSansDispNo1-Bold.woff2>; rel=preload; as=font; type=font/woff2; crossorigin=anonymous;, </assets/fonts/SharpSansDispNo1-Extrabold.woff2>; rel=preload; as=font; type=font/woff2; crossorigin=anonymous;, </assets/fonts/SharpSansDispNo1-MediumIt.woff2>; rel=preload; as=font; type=font/woff2; crossorigin=anonymous;, </assets/fonts/SharpSansDispNo1-BoldIt.woff2>; rel=preload; as=font; type=font/woff2; crossorigin=anonymous;
Upgrade
Other
h2
X-Robots-Tag
Other
noai
X-Rox-0
Other
.---.welcome to roxanne by indigo ascent.
X-Rox-1
Other
.uid.e8395216a2c7e38a24c33ee299b0247e
X-Rox-2
Other
.ver.dbee141d9e84c7e83cb5c49d25a29ac5
X-Rox-3
Other
.sig.::8888888b.:::.d88888b.:Y88b:::d88P::
X-Rox-4
Other
.sig.::888:::Y88b:d88P:::Y88b:Y88b:d88P:::
X-Rox-5
Other
.sig.::888:::d88P:888:::::888:::Y888P:::::
X-Rox-6
Other
.sig.::8888888P:::888:::::888:::d888b:::::
X-Rox-7
Other
.sig.::888::T88b::Y88b.:.d88P:d88P:Y88b:::
X-Rox-8
Other
.sig.::888:::T88b:::Y88888P::d88P:::Y88b::
X-Rox-9
Other
.---.whistles.&.clicks.
Recommendations
Enable compression (gzip/brotli) to improve performance
Analysis completed in 964ms