Open
Cached
·
just now
16
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains
Content-Security-Policy
Basic
default-src; script-src; child-src; +10 more
default-src 'self' data:; script-src 'unsafe-inline' 'unsafe-eval' 'self' *.google.com https://c.amazon-adsystem.com https://www.clarity.ms *.clarity.ms extapi.bankfab.com https://tools.eurolandir.com https://tools.euroland.com https://bat.bing.com https://trk.platformance.co https://tagmanager.google.com *.gstatic.com consent.cookiebot.com consentcdn.cookiebot.com maps.googleapis.com *.googleapis.com analytics.twitter.com connect.facebook.net consent.cookiebot.com consentcdn.cookiebot.com googleads.g.doubleclick.net https://www.googleadservices.com maps.googleapis.com *.googleapis.com sc-static.net script.hotjar.com snap.licdn.com static.ads-twitter.com static.hotjar.com *.google-analytics.com https://ssl.google-analytics.com https://www.google.com/recaptcha/api.js https://www.googleadservices.com/pagead/conversion_async.js https://platform.twitter.com/oct.js https://websdk.appsflyer.com *.bankfab.com *.googletagmanager.com https://extend.vimeocdn.com https://player.vimeo.com/api/player.js js-agent.newrelic.com;child-src 'self' *.bankfab.com *.google.com *.gstatic.com; style-src 'unsafe-inline' 'self' *.bankfab.com *.google.com https://www.googletagmanager.com/debug/badge.css https://tagmanager.google.com *.google.ae *.gstatic.com consent.cookiebot.com maps.googleapis.com *.googleapis.com https://fonts.googleapis.com; object-src https://tools.eurolandir.com https://tools.euroland.com *.bankfab.com; base-uri 'self'; connect-src 'self' https://tools.eurolandir.com https://tools.euroland.com https://trk.platformance.co https://bat.bing.com https://c.amazon-adsystem.com https://www.clarity.ms *.clarity.ms https://aax-eu.amazon-adsystem.com https://tagmanager.google.com https://extend.vimeocdn.com https://vimeo.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://in.hotjar.com https://vc.hotjar.io wss://ws7.hotjar.com www.google.com *.googleapis.com https://www.google-analytics.com https://stats.g.doubleclick.net https://ipapi.co/json/ https://consentcdn.cookiebot.com https://wa.appsflyer.com https://wa.onelink.me; font-src 'self' *.bankfab.com https://fonts.gstatic.com https://script.hotjar.com; frame-src https://trk.platformance.co https://extend.vimeocdn.com https://player.vimeo.com/ 'self' https://*.fls.doubleclick.net https://8630187.fls.doubleclick.net https://bid.g.doubleclick.net https://consentcdn.cookiebot.com https://tools.euroland.com tools.euroland.com https://tools.eurolandir.com tools.eurolandir.com https://tr.snapchat.com https://vars.hotjar.com https://www.google.com; img-src 'self' data: *.bankfab.com *.clarity.ms https://maps.googleapis.com https://*.googleapis.com https://bat.bing.com https://*.fls.doubleclick.net https://ad.doubleclick.net https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://googleads.g.doubleclick.net https://*.g.doubleclick.net https://*.google.com https://maps.googleapis.com https://*.googleapis.com https://ssl.gstatic.com https://www.gstatic.com https://maps.gstatic.com https://p.adsymptotic.com https://page-source.com https://px.ads.linkedin.com https://stats.g.doubleclick.net https://www.facebook.com https://www.google-analytics.com https://www.google.ae https://googleads.g.doubleclick.net https://www.google.com https://c.amazon-adsystem.com https://aax-eu.amazon-adsystem.com https://t.co https://linkedin.com; manifest-src 'self'; media-src 'self' *.bankfab.com https://www.bankfab.com https://dr-cd.bankfab.com; worker-src 'none';
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Missing
Not configured
Recommendations
- • Consider adding 'preload' to HSTS for maximum security
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Consider adding Permissions-Policy to control browser features
Performance Headers
1 headers
Connection
Performance
close
Caching Headers
3 headers
Cache-Control
Caching
no-cache, no-store
Expires
Caching
-1
Pragma
Caching
no-cache
Content Headers
2 headers
Content-Length
Content
328112
Content-Type
Content
text/html; charset=utf-8
Server Headers
0 headers
No server headers found
CORS Headers
0 headers
No CORS headers found
Cookies Headers
1 headers
Set-Cookie
Cookies
TS012cd8ca=01acea3e90b4a339707c53846245c7cfe58600799a5d0d971c3b80e5e694cf7a757604fb04180d1f1872e9ee10bad760f9dd5083d9fa6361f8191228df5ccd135b17120ab2b72c4f39de153022499edb07d42bb86493abf4c5cedf4a14599f64d4774cf0991a1f1e08341390018b580920ed416edd1a012dc3c3f28a3bd00a0423265432890a96db31e981a098208442cb8372785a; Path=/; Secure; HttpOnly
Other Headers
3 headers
Date
Other
Thu, 11 Dec 2025 01:56:22 GMT
Request-Context
Other
appId=cid-v1:baa42b8c-f9a6-48e6-b406-b399ab9e7ea3
X-Ms-Middleware-Request-Id
Other
b3a3cdc7-1a41-4604-987c-ef3beb8d77f6
Recommendations
Enable compression (gzip/brotli) to improve performance
Analysis completed in 3877ms