Open
Cached
·
just now
27
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Excellent
max-age=31536000; preload; includeSubDomains
Content-Security-Policy
Basic
default-src; script-src; style-src; +10 more
default-src *.facebook.com *.fbcdn.net *.instagram.com blob:;script-src *.instagram.com static.cdninstagram.com *.facebook.com *.fbcdn.net *.facebook.net 127.0.0.1:* 'nonce-5aHcPkFO' blob: 'self' 'unsafe-eval' https://*.google-analytics.com https://translate.google.com https://apis.google.com https://accounts.google.com;style-src *.instagram.com static.cdninstagram.com data: blob: 'unsafe-inline' *.fbcdn.net *.facebook.com;connect-src *.instagram.com wss://edge-chat.instagram.com connect.facebook.net *.facebook.com facebook.com *.fbcdn.net *.facebook.net wss://*.facebook.com:* ws://localhost:* blob: *.cdninstagram.com wss://*.instagram.com:* 'self' https://meta.privacy-gateway.cloudflare.com/relay;font-src *.instagram.com static.cdninstagram.com data: *.fbcdn.net *.intern.facebook.com *.facebook.com https://fonts.gstatic.com;img-src *.instagram.com *.facebook.com *.fbcdn.net data: *.cdninstagram.com *.whatsapp.net blob: *.fbsbx.com android-webview-video-poster: *.oculuscdn.com *.giphy.com *.tenor.co *.tenor.com www.googleadservices.com *.doubleclick.net *.google.com *.google.co.uk https://www.gstatic.com https://*.google-analytics.com;media-src *.facebook.com *.fbcdn.net *.instagram.com *.cdninstagram.com *.fbsbx.com data: blob: https://*.giphy.com *.tenor.co *.tenor.com;child-src *.facebook.com *.fbcdn.net *.instagram.com data: blob:;frame-src *.instagram.com *.facebook.com *.fbsbx.com fbsbx.com data: www.googleadservices.com *.doubleclick.net *.google.com *.google.co.uk;manifest-src *.facebook.com *.fbcdn.net *.instagram.com data: blob:;object-src *.facebook.com *.fbcdn.net *.instagram.com data: blob:;block-all-mixed-content;upgrade-insecure-requests;
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Present
accelerometer=(self), attribution-reporting=(), autoplay=(), bluetooth=(), camera=(self), ch-device-memory=(), ch-downlink=(), ch-dpr=(), ch-ect=(), ch-rtt=(), ch-save-data=(), ch-ua-arch=(), ch-ua-bitness=(), ch-viewport-height=(), ch-viewport-width=(), ch-width=(), clipboard-read=(), clipboard-write=(self), compute-pressure=(), display-capture=(self), encrypted-media=(), fullscreen=(self), gamepad=(), geolocation=(self), gyroscope=(self), hid=(), idle-detection=(), interest-cohort=(), keyboard-map=(), local-fonts=(), magnetometer=(), microphone=(self), midi=(), otp-credentials=(self), payment=(), picture-in-picture=(self), private-state-token-issuance=(), publickey-credentials-get=(), screen-wake-lock=(), serial=(), shared-storage=(), shared-storage-select-url=(), private-state-token-redemption=(), usb=(), unload=(self), window-management=(), xr-spatial-tracking=();report-to="permissions_policy"
Recommendations
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
Performance Headers
2 headers
Connection
Performance
close
Vary
Performance
Accept-Encoding
Caching Headers
3 headers
Cache-Control
Caching
private, no-cache, no-store, must-revalidate
Expires
Caching
Sat, 01 Jan 2000 00:00:00 GMT
Pragma
Caching
no-cache
Content Headers
2 headers
Content-Length
Content
0
Content-Type
Content
text/html; charset="utf-8"
Server Headers
0 headers
No server headers found
CORS Headers
0 headers
No CORS headers found
Cookies Headers
0 headers
No cookies headers found
Other Headers
12 headers
Alt-Svc
Other
h3=":443"; ma=86400
Content-Security-Policy-Report-Only
Other
default-src *.facebook.com *.fbcdn.net *.instagram.com blob:;script-src *.instagram.com static.cdninstagram.com *.facebook.com *.fbcdn.net *.facebook.net 127.0.0.1:* 'nonce-5aHcPkFO' blob: 'self' https://*.google-analytics.com https://translate.google.com https://apis.google.com https://accounts.google.com 'report-sample';style-src *.instagram.com static.cdninstagram.com data: blob: 'unsafe-inline' *.fbcdn.net *.facebook.com;connect-src *.instagram.com wss://edge-chat.instagram.com connect.facebook.net *.facebook.com facebook.com *.fbcdn.net *.facebook.net wss://*.facebook.com:* ws://localhost:* blob: *.cdninstagram.com wss://*.instagram.com:* 'self' https://meta.privacy-gateway.cloudflare.com/relay;font-src *.instagram.com static.cdninstagram.com data: *.fbcdn.net *.intern.facebook.com *.facebook.com https://fonts.gstatic.com;img-src *.instagram.com *.facebook.com *.fbcdn.net data: *.cdninstagram.com *.whatsapp.net blob: *.fbsbx.com android-webview-video-poster: *.oculuscdn.com *.giphy.com *.tenor.co *.tenor.com www.googleadservices.com *.doubleclick.net *.google.com *.google.co.uk https://www.gstatic.com https://*.google-analytics.com;media-src *.facebook.com *.fbcdn.net *.instagram.com *.cdninstagram.com *.fbsbx.com data: blob: https://*.giphy.com *.tenor.co *.tenor.com;child-src *.facebook.com *.fbcdn.net *.instagram.com data: blob:;frame-src *.instagram.com *.facebook.com *.fbsbx.com fbsbx.com data: www.googleadservices.com *.doubleclick.net *.google.com *.google.co.uk;manifest-src *.facebook.com *.fbcdn.net *.instagram.com data: blob:;object-src *.facebook.com *.fbcdn.net *.instagram.com data: blob:;block-all-mixed-content;report-uri https://www.facebook.com/csp/reporting/?minimize=0;
Date
Other
Sat, 10 Jan 2026 10:45:40 GMT
Document-Policy
Other
include-js-call-stacks-in-crash-reports
Origin-Agent-Cluster
Other
?1
Origin-Trial
Other
ArDvqjFKr1fHThlSM8Kkp74sxlOCFTeqYJMXCGqCG/VJmcYlO/0UavmpqPDit2KppDf1THInNpwA36GmtgPOug8AAAB2eyJvcmlnaW4iOiJodHRwczovL3d3dy5pbnN0YWdyYW0uY29tOjQ0MyIsImZlYXR1cmUiOiJDcmFzaFJlcG9ydGluZ1N0b3JhZ2VBUEkiLCJleHBpcnkiOjE3NzY3Mjk2MDAsImlzU3ViZG9tYWluIjp0cnVlfQ==
Proxy-Status
Other
http_request_error; e_fb_vipaddr="AcOgq93xbun4i5uCptmX-y8UcjIvjcUOOSop8rwe7Wq-rkbMQEfNVMh7TZM4jTs8CEoFm197Hr11Fy3eNIYw0GojUsfHEmGSU_3Zo6Wg"; e_clientaddr="AcMXSKdby3SSZqpmHAzs5WN3GDnDAUVl_95IQkrr3cxKDGozozgWC6SgLdkiwT6hpmC-XxFLvPMunlQdlQ4Ispea0KhmngWh3_3BnhBs91T92lwy9g"; e_upip="AcPBFw9Qz1sdQf7T2cchOOABkVxD6CK24DpnuP-Nyct7JtBvEkc1ay8egJkQMtL9y1pCq0cPX33YXNI9kRfPoCWRYgrCL0FtGAbdc0ldVFo"; e_fb_zone="AcPiSCLKpu9AxU4UtPG4eiGBqqyaJw5kYn9LWZX3HUFxSc2W4CwvhZT8Pjvo9AMr"; e_fb_twtaskhandle="AcOBpD__CU9GeLKDzOgufSXcW-VBs5xixD9RdPV_Ty7_2RfH9Kdq8bJTXok3Iw5dqi-w0z1iwxUq-9qGQy0llKLUDaVxyZb86NLCBid8dw"; e_proxy="AcOxl9rhWKPIrSixjO5mPlUfwys5Ft4EF4LO74-6B6r9TFLWtWhg8AQBaiYIygVfCGMd_ITGkED41KCamYA", http_request_error; e_fb_vipaddr="AcOiHAS91N1d3Ah6UVU13AC6MAZgB4D75HGeycwdT5crHCSmqMxSgatB_r4GnoiMGY7Ovhg6Qw"; e_clientaddr="AcM25A4UQ1THD9YA6KtFTT9dQYaqDvUFWp3xVhGCnQYWp2X1bnb4fPlZk7Xn0gHaowTXC9o-dQqz9nh1dg"; e_upip="AcMwpLu1t7ENVmKucFga6m2utxGPBkdax2Hth42ViuW_pwEIoTO6nu9OtQZkOqyiaupQXuliUr0BkR3PO59vsH30mmrrzSN2aAByAlcw"; e_fb_zone="AcMz24wOEnPJMfbvjHRtM181-CHs86GIoGKwnhn6BKoHixXT2uvPTgAv-TF6Lw"; e_fb_twtaskhandle="AcP1DyFEviYgXmWLfOERDBFqLLGc6z2iR_iRLmaoVivMb9217lI9e0CHa-Ya_DqgfaV6JfYp--_pGimKPpVVMfwldxgvPubnz8g"; e_proxy="AcMJPwqrFppYWcwEo87CdfHv63pox0b2L6xgECJiH-9NOAZb9DnJCENMqxTkoq3n9Y9ChaRtKH0FKMY"
Report-To
Other
{"max_age":2592000,"endpoints":[{"url":"https:\/\/www.facebook.com\/browser_reporting\/coop\/?minimize=0"}],"group":"coop_report","include_subdomains":true}, {"max_age":259200,"endpoints":[{"url":"https:\/\/www.instagram.com\/error\/ig_web_error_reports\/?device_level=unknown&brsid=7593682310746797185&cpp=C3&cv=1031845255&st=1768041940918"}]}
Reporting-Endpoints
Other
coop_report="https://www.facebook.com/browser_reporting/coop/?minimize=0", default="https://www.instagram.com/error/ig_web_error_reports/?device_level=unknown&brsid=7593682310746797185&cpp=C3&cv=1031845255&st=1768041940918"
X-Fb-Connection-Quality
Other
EXCELLENT; q=0.9, rtt=21, rtx=0, c=13, mss=1368, tbw=3542, tp=-1, tpl=-1, uplat=51, ullat=0
X-Fb-Debug
Other
E4SGTgJ6ddmZJvkN3S2IoLA4VMHtBTCoPGkkNXR57XvzJR5qzOcHaBO+wkrqDLUijNdo9Yg+vQeKT3KtEH0Lyg==
X-Stack
Other
www
Recommendations
Enable compression (gzip/brotli) to improve performance