Open Cached · just now
19 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Weak
frame-ancestors; report-uri
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Significantly strengthen CSP directives
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

Performance Headers

2 headers
Connection
Performance
Transfer-Encoding
Transfer-Encoding
Performance
chunked

Caching Headers

2 headers
Cache-Control
Caching
private, no-cache, no-store, max-age=0, must-revalidate
Last-Modified
Caching
Sun, 07 Dec 2025 10:57:24 GMT

Content Headers

1 headers
Content-Type
Content
text/html; charset=utf-8

Server Headers

0 headers
No server headers found

CORS Headers

0 headers
No CORS headers found

Cookies Headers

1 headers
Set-Cookie
Cookies
TS01fffdff=010fe95fd02a0b3000ff102e468563cc3a9283b43eb5b32f6e5621ddf466df808681b775a8fb4e1e0f3f9ab84bf949db52cc2f0cfd; path=/; domain=lider.cl

Other Headers

12 headers
Accept-Ch
Other
Downlink, DPR
Content-Security-Policy-Report-Only
Other
default-src data: blob: 'unsafe-eval' 'unsafe-inline' px-client.net px-cdn.net pxchk.net perimeterx.net px-cloud.net https: 'self'; script-src 7299633.collect.igodigital.com ajax.cloudflare.com *.bazaarvoice.com bs.serving-sys.com cdn.evgnet.com/beacon/liderdomicilio/pruebas/scripts/evergage.min.js connect.facebook.net deploy.mopinion.com googleads.g.doubleclick.net *.lider.cl media.richrelevance.com recs.richrelevance.com s3.amazonaws.com/mapcity-assets/leaflet-0.7.3/leaflet.js secure-ds.serving-sys.com services.mapcity.com static.cloudflareinsights.com www.google-analytics.com www.google.com www.googletagmanager.com *.googleapis.com static.hotjar.com script.hotjar.com https://cdn.jsdelivr.net/npm/[email protected]/slick/slick.min.js *.googleadservices.com *.gstatic.com cdn-widgets.chattigo.com media.flixfacts.com media.flixcar.com 'self' 'unsafe-inline' 'unsafe-eval'; object-src 'none'; report-uri https://csp.walmart.com/c/r/liders
Date
Other
Sun, 07 Dec 2025 10:57:24 GMT
Traceparent
Other
00-31016fe66c22ce498a78348a725c4a07-02b061680bfd199d-00
X-Edgeconnect-Midmile-Rtt
Other
0
X-Edgeconnect-Origin-Mex-Latency
Other
2076
X-Envoy-Upstream-Service-Time
Other
1526
X-Glass-Routing
Other
Path=/miclub
X-Opt-Inj
Other
true
X-Queueit-Connector
Other
akamai
X-Tb
Other
1
X-Tb-Optimization-Total-Bytes-Saved
Other
0

Recommendations

Enable compression (gzip/brotli) to improve performance

Analysis completed in 2905ms