Open
Cached
·
just now
21
Headers
Detected Technologies from Headers
AWS CloudFront
Cloudflare
Active incidents
Cloudflare CDN
Active incidents
Facebook
Google AdSense
Google Analytics
Google API JS Client
Google DoubleClick
Google Search
Google Static File Front End
Google Tag Manager
Hotjar
jsDelivr
LinkedIn
New Relic
Nginx
WordPress
Google Cloud
HTTP Security Headers
Status
Strict-Transport-Security
Excellent
max-age=31536000; includeSubDomains; preload
X-Frame-Options
Good
sameorigin
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Present
midi=(), sync-xhr=(self), microphone=(); +4 more
Recommendations
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
Performance Headers
Connection
close
Transfer-Encoding
chunked
Vary
Accept-Encoding
connection: close transfer-encoding: chunked vary: Accept-Encoding
Caching Headers
No caching headers found
Content Headers
Content-Type
text/html; charset=UTF-8
content-type: text/html; charset=UTF-8
Server Headers
server: nginx x-powered-by: Apiki WP Cloud Services
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Cross-Origin-Embedder-Policy-Report-Only
unsafe-none; report-to='default'
Date
Tue, 28 Apr 2026 23:40:00 GMT
Link
rel=https://api.w.org/
rel=alternate
title=JSON
type=application/json
rel=shortlink
X-Content-Security-Policy
default-src 'self'; font-src *;img-src * data:; script-src *; style-src *
X-Permitted-Cross-Domain-Policies
none
cross-origin-embedder-policy-report-only: unsafe-none; report-to='default' date: Tue, 28 Apr 2026 23:40:00 GMT link: <https://gocache.com.br/wp-json/>; rel="https://api.w.org/", <https://gocache.com.br/wp-json/wp/v2/pages/109>; rel="alternate"; title="JSON"; type="application/json", <https://gocache.com.br/>; rel=shortlink x-content-security-policy: default-src 'self'; font-src *;img-src * data:; script-src *; style-src * x-permitted-cross-domain-policies: none
Recommendations
Enable compression (gzip/brotli) to improve performance
Add Cache-Control header to optimize caching
Consider removing X-Powered-By header to hide server technology