18 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Present
same-origin
Permissions-Policy
Missing
Not configured
Recommendations
  • Consider adding 'preload' to HSTS for maximum security
  • Add Content-Security-Policy header to prevent XSS attacks
  • Consider adding Permissions-Policy to control browser features

Performance Headers

3 headers
Connection
Performance
close
Transfer-Encoding
Performance
chunked
Vary
Performance
Accept-Encoding

Caching Headers

2 headers
Age
Caching
28793
Cache-Control
Caching
public,max-age=0,must-revalidate

Content Headers

1 headers
Content-Type
Content
text/html; charset=UTF-8

Server Headers

1 headers
Server
Server
cloudflare

CORS Headers

0 headers
No CORS headers found

Cookies Headers

0 headers
No cookies headers found

Other Headers

6 headers
Cache-Status
Other
"Netlify Edge"; hit
Cf-Cache-Status
Other
DYNAMIC
Cf-Ray
Other
9bf33131688b062e-IAD
Date
Other
Sat, 17 Jan 2026 04:43:31 GMT
Link
Other
</webpack-runtime-40f953f884047f76ec1c.js>; rel=preload; as=script, </framework-dd96dd5d8f918457f672.js>; rel=preload; as=script, </af13d906-73193834e49e33999d5c.js>; rel=preload; as=script, </cb1608f2-80901aa554351269358f.js>; rel=preload; as=script, </a9a7754c-f14cfcb10ea136e94767.js>; rel=preload; as=script, </app-27647e7d847919eeb1ac.js>; rel=preload; as=script, </component---src-templates-content-page-js-a9e608632d54e0b321d5.js>; rel=preload; as=script, </page-data/app-data.json>; rel=preload; as=fetch; crossorigin, </page-data/index/page-data.json>; rel=preload; as=fetch; crossorigin
X-Nf-Request-Id
Other
01KF547YR4DWVBDZX3MH46GQN1

Recommendations

Enable compression (gzip/brotli) to improve performance