21 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31536000
Content-Security-Policy
Basic
script-src; script-src-attr; connect-src; +13 more Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Improve CSP by adding more specific directives and removing 'unsafe-inline'
  • Consider adding Permissions-Policy to control browser features

Performance Headers

Connection
Performance
close

Caching Headers

Cache-Control
Caching
no-store, max-age=0
Etag
Caching
W/"9-R1yEhnOj95+nePAcK9WnIdTEFwc"

Content Headers

Content-Language
Content
en
Content-Length
Content
9
Content-Type
Content
text/html; charset=utf-8

Server Headers

No server headers found

CORS Headers

Access-Control-Allow-Origin
Cors
*

Cookies Headers

Set-Cookie
Cookies

Other Headers

Akamai-Console-Grn
Other
0.d70c0317.1787130082.42e9fc59
Date
Other
Wed, 19 Aug 2026 09:01:22 GMT
X-Akamai-Transformed
Other
0 - 0 -
X-Envoy-Upstream-Service-Time
Other
10
X-Response-Time
Other
4.566
X-Transaction-Id
Other
7955c177-aadd-4f3e-9cb1-feafe0b64c1e

Recommendations

Enable compression (gzip/brotli) to improve performance