Open
Cached
·
just now
21
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=86400 ; includeSubDomains
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
2 headers
Connection
Performance
Transfer-Encoding
Transfer-Encoding
Performance
chunked
Caching Headers
3 headers
Cache-Control
Caching
max-age=0, no-cache, no-store
Expires
Caching
Wed, 14 Jan 2026 13:19:58 GMT
Pragma
Caching
no-cache
Content Headers
1 headers
Content-Type
Content
text/html; charset=utf-8
Server Headers
0 headers
No server headers found
CORS Headers
0 headers
No CORS headers found
Cookies Headers
1 headers
Set-Cookie
Cookies
bm_sz=ABAEA9B1CB7E2364D00A8D33170D416D~YAAQ98gwF07EUoubAQAA1bupvB6svW/FdMV1UvJwO7ewbTbCyBXChbbkTQWbRl+ZICvwWkDBmRVzVR2QnFm8ef2cUm97ryeP4moO9TRFXiXs2mZ0dtVSwBy5fIj3iErSzuzUg8fX8aVlQ0dfhni0ae12qrXs/gWI0qM4kAHPr2PFoH7JvL8rVTYTcXFH8jztlj9YCZt/b35kJ44Zc8ELgNKZqmQaCKIhyinR0XzlSqjSCEGFnnlaNXm66BofKt1FTyyHhke6z/gWNE9MvCcgtQoYhluivLE/S9oMkjWyva4m8u9D7yzdHTzOClUNu54g0ljBZA1dV7CTebwSuwq2q5PD6eMhb6wlb5KpO0Ng~3425089~3355462; Domain=.marriott.com; Path=/; Expires=Wed, 14 Jan 2026 17:19:58 GMT; Max-Age=14400
Other Headers
12 headers
Akamai-Grn
Other
0.f7c83017.1768396798.e9633421
Date
Other
Wed, 14 Jan 2026 13:19:58 GMT
Er_information
Other
ER_EXECUTED:;ER_EXECUTED_RULE:
Phoenix
Other
true
Pr_information
Other
PR_EXECUTED:1;PR_EXECUTED_RULE:6403ffd2970aebe3
Retry-After
Other
28800
Server-Timing
Other
ak_p; desc="1768396798719_389073143_3915592737_90_20473_2_7_-";dur=1
X-Akamai-Transformed
Other
9 70235 0 pmb=mTOE,2
X-Oneagent-Js-Injection
Other
true
X-Request-Id
Other
/brands/citizenm.mi~X~7429CED8-2F44-5603-A29D-93DCC04BEAE1
X-Ruxit-Js-Agent
Other
true
X-Service-Id
Other
mi-nginx-app-blue-64fb57b6bf-hcpzm
Recommendations
Enable compression (gzip/brotli) to improve performance