Open
Cached
·
just now
24
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Excellent
max-age=31536000; includeSubDomains; preload
Content-Security-Policy
Weak
upgrade-insecure-requests; connect-src
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Present
same-origin
Permissions-Policy
Present
accelerometer=*, autoplay=*, camera=(), display-capture=(), encrypted-media=*, fullscreen=*, geolocation=(), gyroscope=*, magnetometer=(), microphone=(), midi=(), payment=*, picture-in-picture=*, publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=*, usb=(), web-share=(), xr-spatial-tracking=(), clipboard-read=(), clipboard-write=*, gamepad=(), hid=(), idle-detection=(), interest-cohort=(), serial=(), unload=()
Recommendations
- • Significantly strengthen CSP directives
Performance Headers
3 headers
Connection
Performance
close
Transfer-Encoding
Performance
chunked
Vary
Performance
Origin
Caching Headers
3 headers
Cache-Control
Caching
private, max-age=10800
Expires
Caching
Thu, 19 Nov 1981 08:52:00 GMT
Last-Modified
Caching
Tue, 10 Feb 2026 18:07:16 GMT
Content Headers
1 headers
Content-Type
Content
text/html; charset=UTF-8
Server Headers
2 headers
Server
Server
<3
X-Powered-By
Server
<3
CORS Headers
0 headers
No CORS headers found
Cookies Headers
1 headers
Set-Cookie
Cookies
BSSessId=af6ed86e09ab39cec381ce773cc1183a; path=/; domain=.bannersnack.com
Other Headers
7 headers
Alt-Svc
Other
h3=":443"; ma=86400
Date
Other
Wed, 11 Feb 2026 10:08:04 GMT
Via
Other
1.1 44147ec36a13b8400f9afbf3bfc1f8d8.cloudfront.net (CloudFront)
X-Amz-Cf-Id
Other
Yzry4vKB_-7kl97ct9YRlDNt-jOBBboA0AHHoPuWoPnE3FDstDH52Q==
X-Amz-Cf-Pop
Other
IAD61-P10
X-Cache
Other
Miss from cloudfront
X-Fastcgi-Cache
Other
BYPASS
Recommendations
Enable compression (gzip/brotli) to improve performance
Consider removing X-Powered-By header to hide server technology