Cached · just now
22 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=15768000
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Present
same-origin
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Consider adding Permissions-Policy to control browser features

Performance Headers

2 headers
Connection
Performance
close
Vary
Performance
Cookie,Accept-Encoding

Caching Headers

2 headers
Cache-Control
Caching
max-age=0, no-cache, no-store, must-revalidate, private
Expires
Caching
Sun, 25 Jan 2026 17:31:22 GMT

Content Headers

3 headers
Content-Language
Content
fr
Content-Length
Content
86733
Content-Type
Content
text/html; charset=utf-8

Server Headers

1 headers
Server
Server
nginx

CORS Headers

0 headers
No CORS headers found

Cookies Headers

1 headers
Set-Cookie
Cookies
sessionid=ojy7gdqz0kqte564c1lpr0uqdbffxnfc; expires=Mon, 26 Jan 2026 17:31:22 GMT; HttpOnly; Max-Age=86400; Path=/; SameSite=Lax; Secure

Other Headers

8 headers
Content-Security-Policy-Report-Only
Other
default-src 'self' * blob: * data: *.youtube.com *.facebook.com connect.facebook.net cdnjs.cloudflare.com www.google.com stats.g.doubleclick.net appvizer.one wss://nexus-websocket-a.intercom.io *.stripe.com *.intercom.io *.hotjar.com *.appvizer.one googletagmanager.com www.googletagmanager.com bat.bing.com snap.licdn.com www.google-analytics.com *.mxpnl.com *.googleapis.com *.gstatic.com dc.ads.linkedin.com snap.licdn.com static.hotjar.com cdn4.mxpnl.com widget.intercom.io google-analytics.com *.mixpanel.com *.intercomcdn.com d3js.org snap.licdn.com www.google-analytics.com/analytics.js cdn4.mxpnl.com/libs/mixpanel-2-latest.min.js 'unsafe-inline' 'unsafe-eval'; report-uri /csp/report/
Date
Other
Sun, 25 Jan 2026 17:31:22 GMT
Via
Other
1.1 64c95802ff188dd41dd32c313bef089c.cloudfront.net (CloudFront)
X-Amz-Cf-Id
Other
bNTIlpnse--dmhN1gP5WeAPW83VH_SwdmGSzNtynWVWuSk4XQ4iHoA==
X-Amz-Cf-Pop
Other
IAD61-P1
X-Cache
Other
Miss from cloudfront
X-Iplb-Instance
Other
65975
X-Iplb-Request-Id
Other
12441E0B:3002_36264023:01BB_6976536A_11940A3:E917

Recommendations

Enable compression (gzip/brotli) to improve performance