Open Cached · just now
27 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Consider adding 'preload' to HSTS for maximum security
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

Performance Headers

2 headers
Connection
Performance
Transfer-Encoding
Transfer-Encoding
Performance
chunked

Caching Headers

3 headers
Cache-Control
Caching
max-age=0, no-cache, no-store
Expires
Caching
Fri, 21 Nov 2025 06:53:36 GMT
Pragma
Caching
no-cache

Content Headers

1 headers
Content-Type
Content
text/html; charset=UTF-8

Server Headers

2 headers
Server
Server
TLB
X-Powered-By
Server
Goofy Node

CORS Headers

0 headers
No CORS headers found

Cookies Headers

0 headers
No cookies headers found

Other Headers

18 headers
Date
Other
Fri, 21 Nov 2025 06:53:36 GMT
Server-Timing
Other
inner; dur=415,inner; dur=380,bd-edenx-server-loader;decs="SSR"; dur=19.000053, bd-edenx-ssr-render-html;decs="SSR"; dur=125
X-Akamai-Request-Id
Other
20fa0d3.41f13e3
X-Bytefaas-Enable-Stream
Other
true
X-Bytefaas-Execution-Duration
Other
364.76
X-Bytefaas-Request-Id
Other
202511211453366317A8499862A5084471
X-Cache
Other
TCP_MISS from a23-220-105-83.deploy.akamaitechnologies.com (AkamaiGHost/22.3.2.1-811eb0bc095268e0c68e3c1c2197f35a) (-)
X-Cache-Remote
Other
TCP_MISS from a23-34-163-111.deploy.akamaitechnologies.com (AkamaiGHost/22.3.2.1-811eb0bc095268e0c68e3c1c2197f35a) (-)
X-Ggw-Config-Version
Other
100935
X-Gw-Dst-Psm
Other
goofy_ssr.sgcomm.1499152
X-Modernjs-Render
Other
server
X-Origin-Response-Time
Other
452,23.34.163.111
X-Parent-Response-Time
Other
665,23.220.105.83
X-Processed-By
Other
Modern.js
X-Tt-Logid
Other
202511211453366317A8499862A5084471
X-Tt-Trace-Host
Other
01eaa1522d197f1bd9e9d0828f2dbafc28053ca9ded97e2e8968e94502cdd771c4a32aec1518a4b355ae4c8ddc7227aac874a86c700cc8b74141189c19f0d4eb996c485c655c1e5146378b8f18159f3628ceb36aa68f70debd9e15d2289dde4bb2
X-Tt-Trace-Id
Other
00-2511211453366317A8499862A5084471-38FCE9204985AF45-00
X-Tt-Trace-Tag
Other
id=16;cdn-cache=miss;type=dyn

Recommendations

Enable compression (gzip/brotli) to improve performance

Consider removing X-Powered-By header to hide server technology

Analysis completed in 1101ms