Open
Cached
·
just now
25
Headers
Detected Technologies from Headers
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Present
origin-when-cross-origin
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Significantly strengthen CSP directives
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Accept-Ranges
bytes
Connection
close
Transfer-Encoding
chunked
Vary
Accept-Encoding
accept-ranges: bytes connection: close transfer-encoding: chunked vary: Accept-Encoding
Caching Headers
Cache-Control
private, no-store
cache-control: private, no-store
Content Headers
Content-Language
en-US
Content-Type
text/html;charset=UTF-8
content-language: en-US content-type: text/html;charset=UTF-8
Server Headers
Server
KAYAK/1.0
server: KAYAK/1.0
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Date
Sun, 10 May 2026 05:11:58 GMT
Feature-Policy
camera 'none'; microphone 'none'; midi 'none'; usb 'none'; geolocation 'self'
X-Cache
MISS, MISS
X-Cache-Hits
0, 0
X-R9-Mst-Req
016000067427230
X-R9-Mst-Target
sparkle
X-Render-Time
0.149
X-Served-By
cache-ewr-kewr1740071-EWR, cache-ewr-kewr1740071-EWR
X-Sn-Waf-Code
X-Timer
S1778389918.381271,VS0,VE200
date: Sun, 10 May 2026 05:11:58 GMT feature-policy: camera 'none'; microphone 'none'; midi 'none'; usb 'none'; geolocation 'self' via: 1.1 varnish x-cache: MISS, MISS x-cache-hits: 0, 0 x-r9-mst-req: 016000067427230 x-r9-mst-target: sparkle x-render-time: 0.149 x-served-by: cache-ewr-kewr1740071-EWR, cache-ewr-kewr1740071-EWR x-sn-waf-code: x-timer: S1778389918.381271,VS0,VE200
Recommendations
Enable compression (gzip/brotli) to improve performance