Open Cached · just now
13 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31536000; preload
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

Performance Headers

2 headers
Connection
Performance
keep-alive
Transfer-Encoding
Performance
chunked

Caching Headers

3 headers
Cache-Control
Caching
no-store, no-cache, must-revalidate
Expires
Caching
Thu, 19 Nov 1981 08:52:00 GMT
Pragma
Caching
no-cache

Content Headers

1 headers
Content-Type
Content
text/html; charset=UTF-8

Server Headers

1 headers
Server
Server
nginx

CORS Headers

0 headers
No CORS headers found

Cookies Headers

1 headers
Set-Cookie
Cookies
prices_with_tax_1_0=0; expires=Thu, 05-Nov-2026 16:51:53 GMT; Max-Age=31536000; path=/; domain=www.loopia.se

Other Headers

2 headers
Content-Security-Policy-Report-Only
Other
default-src 'self'; report-uri https://csp.loopia.se; connect-src 'self' https://*.analytics.google.com https://*.loopia.com https://*.loopia.no https://*.loopia.rs https://*.loopia.se https://adservice.google.com https://analytics.google.com https://api.exponea.com https://api.infinario.com https://bat.bing.com https://cdn.linkedin.oribi.io https://chat.puzzel.com https://content.hotjar.io https://datainsights.loopia.se https://in.hotjar.com https://sc.lfeeder.com https://stats.g.doubleclick.net https://vc.hotjar.io https://www.facebook.com https://www.google-analytics.com https://www.google.be https://www.google.com https://www.google.se wss://*.hotjar.com; font-src 'self' https://*.loopia.com https://*.loopia.no https://*.loopia.rs https://*.loopia.se https://chat.puzzel.com https://fonts.gstatic.com https://tpc.googlesyndication.com; form-action 'self' https://*.loopia.com https://*.loopia.no https://*.loopia.rs https://*.loopia.se https://bib.eway2pay.com https://payment.architrade.com https://ticket.siriusit.net https://www.facebook.com; frame-src 'self' https://*.facebook.com https://*.mynewsdesk.com https://*.soundcloud.com https://1-vbus-eu.ladesk.com https://active24.ladesk.com https://datainsights.loopia.se https://googleads.g.doubleclick.net https://player.vimeo.com https://tpc.googlesyndication.com https://vars.hotjar.com https://widget.trustpilot.com https://www.googletagmanager.com https://www.youtube.com; img-src 'self' data: https://*.ads.linkedin.com https://*.loopia.com https://*.loopia.no https://*.loopia.rs https://*.loopia.se https://*.ytimg.com https://bat.bing.com https://chat.puzzel.com https://fonts.gstatic.com https://googleads.g.doubleclick.net https://sealserver.trustkeeper.net https://ssl.google-analytics.com https://stats.g.doubleclick.net https://tbs.tradedoubler.com https://tr.lfeeder.com https://track.adform.net https://track.double.net https://www.facebook.com https://www.google-analytics.com https://www.google.be https://www.google.com https://www.google.com.cy https://www.google.es https://www.google.fi https://www.google.gr https://www.google.no https://www.google.rs https://www.google.se https://www.googletagmanager.com https://www.gstatic.com https://www.linkedin.com; media-src 'self' https://*.loopia.com https://*.loopia.no https://*.loopia.rs https://*.loopia.se https://chat.puzzel.com; object-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://*.loopia.com https://*.loopia.no https://*.loopia.rs https://*.loopia.se https://*.ytimg.com https://active24.ladesk.com https://api.exponea.com https://api.infinario.com https://bat.bing.com https://chat.puzzel.com https://connect.facebook.net https://g.microsoft.com https://googleads.g.doubleclick.net https://sc.lfeeder.com https://script.hotjar.com https://snap.licdn.com https://ssl.google-analytics.com https://static.hotjar.com https://tpc.googlesyndication.com https://widget.trustpilot.com https://www.google-analytics.com https://www.google.com https://www.google.se https://www.googleadservices.com https://www.googletagmanager.com https://www.googletagmanager.com https://www.youtube.com; script-src-elem 'self' 'unsafe-eval' 'unsafe-inline' https://*.loopia.com https://*.loopia.no https://*.loopia.rs https://*.loopia.se https://*.ytimg.com https://active24.ladesk.com https://api.exponea.com https://api.infinario.com https://bat.bing.com https://chat.puzzel.com https://connect.facebook.net https://g.microsoft.com https://googleads.g.doubleclick.net https://sc.lfeeder.com https://script.hotjar.com https://snap.licdn.com https://ssl.google-analytics.com https://static.hotjar.com https://tpc.googlesyndication.com https://widget.trustpilot.com https://www.google-analytics.com https://www.google.com https://www.google.se https://www.googleadservices.com https://www.googletagmanager.com https://www.googletagmanager.com https://www.gstatic.com https://www.youtube.com; style-src 'self' 'unsafe-inline' https://*.loopia.com https://*.loopia.no https://*.loopia.rs https://*.loopia.se https://chat.puzzel.com https://fonts.googleapis.com
Date
Other
Wed, 05 Nov 2025 16:51:53 GMT

Recommendations

Enable compression (gzip/brotli) to improve performance

Analysis completed in 1421ms