Cached · just now
28 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Excellent
max-age=63072000;includeSubDomains;preload
Content-Security-Policy
Weak
upgrade-insecure-requests; frame-ancestors; object-src Analyze
Content-Security-Policy-Report-Only
Basic
script-src; base-uri; report-uri; +1 more Analyze
X-Frame-Options
Excellent
deny
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Present
bluetooth=(), camera=(), clipboard-read=(); +11 more
Recommendations
  • Significantly strengthen CSP directives

Performance Headers

Accept-Ranges
Performance
bytes
Connection
Performance
close
Vary
Performance
Accept-Encoding,User-Agent,Sec-CH-UA-Mobile

Caching Headers

Age
Caching
0
Cache-Control
Caching
no-store
Etag
Caching
W/"3d837-VIIwXkLdUWSGVY2epFKmXZoEpxE"

Content Headers

Content-Length
Content
227533
Content-Type
Content
text/html; charset=utf-8

Server Headers

No server headers found

CORS Headers

No CORS headers found

Cookies Headers

Set-Cookie
Cookies

Other Headers

Date
Other
Sun, 10 May 2026 19:42:12 GMT
Document-Policy
Other
include-js-call-stacks-in-crash-reports
Feature-Policy
Other
camera 'none';display-capture 'none';geolocation 'none';microphone 'none';payment 'none';usb 'none';xr-spatial-tracking 'none'
Nel
Other
Report-To Group default max-age: 1y
success: 0.5% include subdomains
Origin-Agent-Cluster
Other
?1
Report-To
Other
Group default max-age: 1y
Server-Timing
Other
gnt_i;desc="30934664397419561076*30081*US~IL~chicago~60602*h~x"
X-Cache
Other
MISS, MISS, MISS
X-Robots-Tag
Other
noarchive,nocache

Recommendations

Enable compression (gzip/brotli) to improve performance