Open
Cached
·
just now
17
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains
Content-Security-Policy
Basic
default-src; style-src; script-src; +4 more
default-src 'self' data: * cdn.cookie-script.com;style-src 'self' 'unsafe-inline' fonts.googleapis.com code.ionicframework.com blueimp.github.io cdnjs.cloudflare.com maxcdn.bootstrapcdn.com ajax.googleapis.com cdn.jsdelivr.net embed.tawk.to tagmanager.google.com *.bunny.net cdn.cookie-script.com report.cookie-script.com;script-src 'self' blob: 'unsafe-inline' 'unsafe-eval' www.google-analytics.com www.google.com www.gstatic.com www.googletagmanager.com maps.googleapis.com ssl.google-analytics.com www.googleadservices.com connect.facebook.net googleads.g.doubleclick.net ajax.googleapis.com snap.licdn.com *.linkedin.com cdnjs.cloudflare.com cdn.ckeditor.com static.doubleclick.net maxcdn.bootstrapcdn.com storage.trafic.ro secure.trafic.ro cdn.jsdelivr.net embed.tawk.to static.hotjar.com script.hotjar.com *.googlesyndication.com *.google.ro *.google.com *.googleadservices.com *.twitter.com *.linkedin.com tagmanager.google.com *.googletagmanager.com cdn.cookie-script.com report.cookie-script.com;font-src 'self' data: cdnjs.cloudflare.com fonts.gstatic.com maxcdn.bootstrapcdn.com code.ionicframework.com embed.tawk.to *.bunny.net cdn.cookie-script.com;img-src 'self' blob: data: http: https: www.google-analytics.com stats.g.doubleclick.net www.google.com maps.googleapis.com maps.gstatic.com www.google.ro *.facebook.com img.youtube.com i.ytimg.com cdn.ckeditor.com ajax.googleapis.com www.googletagmanager.com ssl.gstatic.com www.gstatic.com *.google-analytics.com *.googletagmanager.com *.analytics.google.com *.g.doubleclick.net *.google.com googleads.g.doubleclick.net ad.doubleclick.net ade.googlesyndication.com cdn.cookie-script.com mediamed.ro;frame-src 'self' www.google.com www.youtube.com www.youtube-nocookie.com youtube.com youtu.be *.facebook.com *.facebook.net cdnjs.cloudflare.com cdn.ckeditor.com vars.hotjar.com googleads.g.doubleclick.net tpc.googlesyndication.com *.twitter.com bid.g.doubleclick.net cdn.cookie-script.com;connect-src 'self' www.google.com *.google.com www.google.ro *.google.ro www.google-analytics.com *.google-analytics.com stats.g.doubleclick.net www.facebook.com *.facebook.com *.facebook.net www.youtube.com *.youtube.com *.cloudflare.com *.tawk.to hotjar.com *.hotjar.com wss://*.hotjar.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.g.doubleclick.net captcha.advancedideas.ro cdn.cookie-script.com consent.cookie-script.com;
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Present
geolocation=(self "https://mediamed.ro")
Recommendations
- • Consider adding 'preload' to HSTS for maximum security
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
Performance Headers
3 headers
Connection
Performance
close
Transfer-Encoding
Performance
chunked
Vary
Performance
Accept-Encoding,User-Agent
Caching Headers
3 headers
Cache-Control
Caching
max-age=0, must-revalidate, no-cache, no-store, private
Expires
Caching
Fri, 01 Jan 1990 00:00:00 GMT
Pragma
Caching
no-cache
Content Headers
1 headers
Content-Type
Content
text/html; charset=utf-8
Server Headers
1 headers
Server
Server
nginx
CORS Headers
0 headers
No CORS headers found
Cookies Headers
1 headers
Set-Cookie
Cookies
media_med_publicis_session=eyJpdiI6IkRrUzNwaEhEcGhmcUhPVHErc0JxbXc9PSIsInZhbHVlIjoieE13ZWFINGVWOW1INTVXdDdSYXh2bGg2Q2phbUhMdHJ0WkNHKzBmdGtTQVhrWVNxcno2ZE9la2ZBNkluTzB3YkRKbjBNdks1WGFQWGQrZkJHM09ZVHJaUjVVWEsyUU1aNmo1VEJoVnZRRkFFMlo3SU9IbFRwa1kxdVhxV1hYQlciLCJtYWMiOiIxY2MzOTAzYWJiYjA2ZmMwZTc4NGIxNGM1MmE5ZmZjMDJkNmMwZDYyZTBlMThkNWZiMTE2ZjE4NWRlZmMxMmZmIiwidGFnIjoiIn0%3D; path=/; secure; httponly; samesite=lax
Other Headers
1 headers
Date
Other
Thu, 25 Dec 2025 22:28:25 GMT
Recommendations
Enable compression (gzip/brotli) to improve performance
Analysis completed in 1304ms