Open Cached · just now
13 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Weak
frame-ancestors
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Significantly strengthen CSP directives
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

Performance Headers

2 headers
Connection
Performance
keep-alive
Transfer-Encoding
Performance
chunked

Caching Headers

1 headers
Cache-Control
Caching
no-cache

Content Headers

1 headers
Content-Type
Content
text/html; charset=utf-8

Server Headers

2 headers
Server
Server
nginx
X-Runtime
Server
0.010054

CORS Headers

0 headers
No CORS headers found

Cookies Headers

1 headers
Set-Cookie
Cookies
_sw_session=QUEzRFgvaHZHODg1c2FWS1BnMFJMTUNwVGVlTjFBMUViVXdxY2pOakhZZW8vOS9lQjRJYnZBS0VvYTBXT1pGd04vZ3d1VjNucDdCdmtXaEw3aGtqRzB4YWxDQlAxT2RmV1FZYzMzd1VpSnZNdndLYkN2a2t1UmdKR3JWTVdubm9adENBbm5QdExCU1lMQ1FrVGN5a2VUWTNFZnhGM3E5TmZ5WE5ha1hzK3JsQ2tncjVYOWs5d3pzV1pWcEN3NEU2czg4NmZzKzJrc3BQT0lXWFZ6aFQxb2dvelFtMTlCOWlIQTdmNGk0bmVzST0tLW1pQzVjV2pBN2RQRXQwcmtsYWt0S1E9PQ%3D%3D--e0471924afbc1743a35f90b0d09932bfb847ae0e; path=/; secure; HttpOnly; SameSite=None

Other Headers

2 headers
Date
Other
Tue, 18 Nov 2025 02:17:02 GMT
X-Request-Id
Other
484d1bde-3960-4aa8-a896-6fed973c58b7

Recommendations

Enable compression (gzip/brotli) to improve performance

Analysis completed in 528ms