11 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

Performance Headers

Connection
Performance
close
Transfer-Encoding
Performance
chunked
Vary
Performance
Origin

Caching Headers

Cache-Control
Caching
no-transform,public,max-age=3600,s-maxage=10800
Expires
Caching
Sat, 04 Apr 2026 01:37:27 GMT

Content Headers

No content headers found

Server Headers

No server headers found

CORS Headers

No CORS headers found

Cookies Headers

No cookies headers found

Other Headers

Date
Other
Sat, 04 Apr 2026 00:37:27 GMT
P3p
Other
policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CUR ADM DEV OUR BUS"
X-Error
Other
unknown resource
X-Region
Other
us-east-1
X-Serverid
Other
uconnect_uconnect-013f605a-f6b8-49c8-81a7-e0b81b657271
X-Ulver
Other
45d57906f01af5f12811e7c1609f8a78de9a9fe3-SNAPSHOT

Recommendations

Enable compression (gzip/brotli) to improve performance