Open
Cached
·
just now
16
Headers
Detected Technologies from Headers
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Present
no-referrer-when-downgrade, strict-origin-when-cross-origin
Permissions-Policy
Present
interest-cohort=()
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
Performance Headers
Connection
Upgrade, close
Transfer-Encoding
chunked
Vary
Origin,Cookie,User-Agent,Accept-Encoding
connection: Upgrade, close transfer-encoding: chunked vary: Origin,Cookie,User-Agent,Accept-Encoding
Caching Headers
Age
895
Cache-Control
max-age=60, private, s-maxage=900
age: 895 cache-control: max-age=60, private, s-maxage=900
Content Headers
Content-Type
text/html; charset=UTF-8
content-type: text/html; charset=UTF-8
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Contao-Cache
fresh
Date
Thu, 09 Apr 2026 09:42:13 GMT
Upgrade
h2,h2c
X-Content-Digest
en8767b34ec43e067957fa2cbbc5eedae92a18478823256b2da300f6354285fe4e
contao-cache: fresh date: Thu, 09 Apr 2026 09:42:13 GMT upgrade: h2,h2c x-content-digest: en8767b34ec43e067957fa2cbbc5eedae92a18478823256b2da300f6354285fe4e
Recommendations
Enable compression (gzip/brotli) to improve performance