Open Cached · just now
18 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Weak
max-age=0; includeSubDomains
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Consider adding Permissions-Policy to control browser features

Performance Headers

3 headers
Connection
Performance
keep-alive
Transfer-Encoding
Performance
chunked
Vary
Performance
Accept-Encoding

Caching Headers

1 headers
Cache-Control
Caching
public, max-age=0, must-revalidate

Content Headers

1 headers
Content-Type
Content
text/html; charset=utf-8

Server Headers

1 headers
Server
Server
cloudflare

CORS Headers

1 headers
Access-Control-Allow-Origin
Cors
*

Cookies Headers

0 headers
No cookies headers found

Other Headers

7 headers
Cf-Cache-Status
Other
DYNAMIC
Cf-Ray
Other
99884da69a55d639-IAD
Content-Security-Policy-Report-Only
Other
default-src 'self' https://n8n.io data: 'unsafe-inline'; script-src 'self' 'sha256-4pl9dZH8ght2nZ3AX1mV23mwuukxsklzULVnAeIEKbg=' https://cdn.jsdelivr.net/npm/@webcomponents/[email protected]/webcomponents-loader.js https://www.unpkg.com/[email protected]/polyfill-support.js https://cdn.jsdelivr.net/npm/@n8n_io/n8n-demo-component@latest/n8n-demo.bundled.js https://*.googletagmanager.com https://www.gstatic.cn https://www.gstatic.com https://www.recaptcha.net https://static.cloudflareinsights.com/beacon.min.js/ static.cloudflareinsights.com https://script.tapfiliate.com/tapfiliate.js https://checkout.paddle.com/api/2.0/prices/; img-src 'self' data: https://*.google-analytics.com https://*.googletagmanager.com https://n8niostorageaccount.blob.core.windows.net https://www.gstatic.cn https://www.gstatic.com https://www.recaptcha.net https://gravatar.com/avatar/; media-src https://n8niostorageaccount.blob.core.windows.net; connect-src 'self' https://api.n8n.io/ https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://www.gstatic.cn https://www.gstatic.com https://www.recaptcha.net; frame-src https://jobs.ashbyhq.com https://n8n-preview-service.internal.n8n.cloud https://www.recaptcha.net https://challenges.cloudflare.com https://www.linkedin.com https://buy.paddle.com; frame-ancestors 'none'; object-src 'none'
Date
Other
Mon, 03 Nov 2025 02:04:51 GMT
Nel
Other
{"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Report-To
Other
{"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=4agYRyF3gOuv7%2BCeqzm3axjvQDEcF%2BJdwVZYvYVA7PiCKYcvyiRXx4tyQ%2FEKGnQBdT8QjgoeWYyRqJHiA%2FBNNi2pFaT9ANlWgjgHy7DOUie6Oh3gFOvouBc%3D"}],"group":"cf-nel","max_age":604800}
Server-Timing
Other
cfEdge;dur=49,cfOrigin;dur=0

Recommendations

Enable compression (gzip/brotli) to improve performance

Analysis completed in 68ms