6 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

Performance Headers

Connection
Performance
close

Caching Headers

No caching headers found

Content Headers

Content-Length
Content
2854
Content-Type
Content
text/html; charset=utf-8

Server Headers

No server headers found

CORS Headers

Access-Control-Allow-Origin
Cors
*

Cookies Headers

No cookies headers found

Other Headers

Date
Other
Tue, 07 Apr 2026 16:38:31 GMT
Proxy-Status
Other
proxy_internal_response; e_fb_vipaddr="AcPLpl0CNgFeBjqLyW76TeKooVUttjdZ9TRKqTE2pzNULJA24yj1m0fNQs4RFNRuTLmE1L0"; e_isproxyerr="AcPqrbWC3Eqt63hAsBblVYVk2WEqGDVGPgVjfiXfhUUev4HrjnuKfx-UHyqJaA"; e_clientaddr="AcM6JjMw_X7H-j48IqGJMZP0G0xxRYcgC9ERI3Zg-UW1BDd_RoIKxe7Cdi_a5WJOVZ6Fz-889S1l_DZaCw0"; e_fb_zone="AcMxWjQ25rSWPyQ46g7GWKNH6x2k03dnMsY-IMeVbmk03wCh-Kp4Pj-Y1-0FlA"; e_fb_twtaskhandle="AcM6sMWHGDzeIT5pIAwYjUJaoyXZI_p_CLipgNXRBgbVXX18Qw-e9CjshMQvkd3Nwcr1rimxY7PpC25R0D2di7eOPQeDBCrTdDW9"; e_proxy="AcO4WucNQ8Ih06QZr0xGt8ZVur-VjZXRzo62-Ckra2ZYVdRndXff2LViVBzPuDe1MEw3Ubsf22G_Nr4"

Recommendations

Enable compression (gzip/brotli) to improve performance

Add Cache-Control header to optimize caching