Open
Cached
·
just now
18
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=15768000
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Consider adding Permissions-Policy to control browser features
Performance Headers
3 headers
Connection
Performance
close
Transfer-Encoding
Performance
chunked
Vary
Performance
Accept-Encoding
Caching Headers
2 headers
Cache-Control
Caching
max-age=0, private, must-revalidate
Etag
Caching
W/"8f4be58692ed689a0f6be5ac0f772af1"
Content Headers
1 headers
Content-Type
Content
text/html; charset=utf-8
Server Headers
2 headers
Server
Server
nginx
X-Runtime
Server
0.044758
CORS Headers
0 headers
No CORS headers found
Cookies Headers
1 headers
Set-Cookie
Cookies
_session_id=ef7f645a31bb1c0833244b22cdbcf309; path=/; expires=Tue, 03 Feb 2026 05:29:00 GMT; secure; HttpOnly
Other Headers
4 headers
Date
Other
Sat, 31 Jan 2026 05:29:00 GMT
Link
Other
<https://cdn.clientcentral.io/assets/app-framework-c0c03f9f23a63a530004d9b36ef71d571989dbad6602375cbea379593ed701a6.css>; rel=preload; as=style; nopush,<https://cdn.clientcentral.io/assets/application-5acf4870c62d96ccde091dad9dc03bcfe1fb1740ea7a220881a4b98b5b3a2637.css>; rel=preload; as=style; nopush,<https://cdn.clientcentral.io/assets/layout-default-824d6ad75d130da85e0f15248b220665e8b12163b00ea58a21a4ce96c127fbcc.css>; rel=preload; as=style; nopush,<https://cdn.clientcentral.io/assets/labs-09a77eba5b59540d3605387c12e6d3eababd62a5d4af1285a9a9534599fa2a44.css>; rel=preload; as=style; nopush,<https://cdn.clientcentral.io/assets/support-b0cb50afd49ddea44b01afd4c09e86b6af95716605dfb819d2c376786c85653c.css>; rel=preload; as=style; nopush,<https://cdn.clientcentral.io/assets/system-quo-663a4535f33aeb0d1523a2f152638439b4001fb5d55cb4a8a728ba9c8d710982.css>; rel=preload; as=style; nopush
X-Permitted-Cross-Domain-Policies
Other
none
X-Request-Id
Other
566d2368-a727-46fe-ac90-8ddeafdfd446
Recommendations
Enable compression (gzip/brotli) to improve performance