Open
Cached
·
just now
19
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Good
max-age=63072000; includeSubDomains
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Missing
Not configured
Recommendations
- • Consider adding 'preload' to HSTS for maximum security
- • Add Content-Security-Policy header to prevent XSS attacks
- • Consider adding Permissions-Policy to control browser features
Performance Headers
2 headers
Connection
Performance
close
Transfer-Encoding
Performance
chunked
Caching Headers
2 headers
Cache-Control
Caching
max-age=0, private, must-revalidate
Etag
Caching
W/"862a06885f363255143ceb6241bed6d3"
Content Headers
1 headers
Content-Type
Content
text/html; charset=utf-8
Server Headers
3 headers
Server
Server
nginx/1.26.2 + Phusion Passenger(R) 6.0.24
X-Powered-By
Server
Phusion Passenger(R) 6.0.24
X-Runtime
Server
0.038578
CORS Headers
0 headers
No CORS headers found
Cookies Headers
1 headers
Set-Cookie
Cookies
_agora_session=3v%2FCJedLm0ZLTi1Y7TGyfgcui%2Frv7pHxrGp3RavMliy1lN%2F0%2FTPo8kGLM9JjrE02rbVKKTNM8tB4UTjrwHefaNW4h1uq6IQ3V%2Bdf6D%2FLFpiqHbeDuiSXGV%2FmoxYFzI%2FAHjMk4waTxuIpLG1nZlZ2OPWqMgivSnAcJgSZWfUWPpYYsMhilIlPe3Ff7zzZ22VKr%2Bx5BiVoLHOu4TjpMgf%2B0E9F9EnYgNL4IdFmy8l3RtSrK5glvYktzDppW6p4TlefdGAhP6buKfyRFnatV4CWUW5taos4uQ%3D%3D--S3wOR6oBWeGyLegX--9Zbh2ihOJVYOHfF1xxa9eQ%3D%3D; path=/; secure; httponly; samesite=lax
Other Headers
5 headers
Date
Other
Thu, 25 Dec 2025 16:02:01 GMT
Link
Other
</assets/application-60d2cbb8e7a80d81d3aa59a536c1ebc5865a69be54e91c740dc9715fa5073bf2.css>; rel=preload; as=style; nopush,</assets/application-681f26782c52b30aa6817fe5d75f0837b1404ab8ef8ed068d1754c686a70da61.js>; rel=preload; as=script; nopush,</packs/css/application-4707e12a.css>; rel=preload; as=style; nopush,</packs/js/application-ae12c38dc4f83e97c351.js>; rel=preload; as=script; nopush
Status
Other
200 OK
X-Permitted-Cross-Domain-Policies
Other
none
X-Request-Id
Other
b1c61137-836b-434c-b509-341f9eed4706
Recommendations
Enable compression (gzip/brotli) to improve performance
Consider removing X-Powered-By header to hide server technology
Analysis completed in 380ms