13 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31536000
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Consider adding Permissions-Policy to control browser features

Performance Headers

1 headers
Connection
Performance
close

Caching Headers

0 headers
No caching headers found

Content Headers

2 headers
Content-Language
Content
en
Content-Length
Content
0

Server Headers

0 headers
No server headers found

CORS Headers

0 headers
No CORS headers found

Cookies Headers

1 headers
Set-Cookie
Cookies
bm_sz=A1C0CECD2E4EC1A68AC10C9D1ADBAB60~YAAQUsgwF5Eb67CaAQAAA8ckyB32580098h7QaSR21sTsd0mYhKSksGnrYJtH9ILXvdjiNxN8O+ysdBlZcS17ZIsSEWV8q7zTfUy9y8xd7Pr6MxK2/yD1CJi4RQ/YYDpTbEC98SfLwJu1XqGkR96f6fPojRqRtFqnPsyru5QeyXYdbQlhy/NKk+MjfS85o2slErWB6qycelNiEa6gkUo0f4HCNp3RdvaGsqGXQd/qZGbj2MjxEytbcLmTVIBphtJ2uAZ1crzpqd54h4EnzxeKITB/Nrdo2tmO2XKfk+smFyGE/5FGMpLzM3E+D006tFYlmMTzBdibsz+rfyR3Qf33K6hu+D0WqWJ+FJ/~3617349~3749701; Domain=.ibm.com; Path=/; Expires=Fri, 28 Nov 2025 05:47:24 GMT; Max-Age=14400; SameSite=None; Secure

Other Headers

4 headers
Akamai-Grn
Other
0.52c83017.1764294444.5626e928
Date
Other
Fri, 28 Nov 2025 01:47:24 GMT
X-Envoy-Upstream-Service-Time
Other
8
X-Response-Time
Other
3.457

Recommendations

Enable compression (gzip/brotli) to improve performance

Add Cache-Control header to optimize caching

Analysis completed in 46ms