Open
Cached
·
just now
20
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=63072000; includeSubdomains; preload
Content-Security-Policy
Good
upgrade-insecure-requests; base-uri; default-src; +10 more
upgrade-insecure-requests; base-uri 'self'; default-src https://*.credilio.in https://*.credilio.org https://*.noviolife.in https://*.credilio.info https://*.novio.in https://*.novio.co.in https://*.easycardsloans.com https://vimeo.com https://*.vimeo.com https://*.google-analytics.com https://*.googletagmanager.com https://*.google.com https://fonts.gstatic.com https://*.facebook.com https://*.gotrackier.com https://*.sbicard.com https://*.googleapis.com https://*.firebaseapp.com https://*.iconify.design https://*.esbeeyem.com:9443 https://*.esbeeyem.com https://sdk-api-v1.singular.net https://bam.nr-data.net https://www.googleadservices.com https://td.doubleclick.net https://www.google.co.in https://cdn.jsdelivr.net; img-src 'self' data: https://*.credilio.in/ https://*.credilio.org https://*.noviolife.in https://*.credilio.info/ https://*.novio.in https://*.novio.co.in https://*.easycardsloans.com/ https://*.vimeocdn.com https://*.facebook.com https://*.doubleclick.net https://*.google.com https://*.google.co.in https://*.gotrackier.com https://*.follow.whistle.mobi https://*.whistle.mobi https://www.googletagmanager.com; script-src 'self' 'unsafe-inline' https:; style-src 'self' 'unsafe-inline' https:; object-src 'self'; manifest-src 'self'; font-src 'self' https:; frame-ancestors 'self'; frame-src 'self' https://td.doubleclick.net/ https://*.firebaseapp.com https://www.googletagmanager.com https://cdn.credilio.in https://player.vimeo.com; form-action 'self' https://*.hdfcbank.com https://*.sbicard.com https://*.sbmbank.co.in https://*.esbeeyem.com:9443 https://*.esbeeyem.com https://td.doubleclick.net https://*.hdfc.bank.in https://*.sbm.bank.in; media-src https://*.s3.amazonaws.com https://*.credilio.in https://*.credilio.org https://*.noviolife.in https://*.credilio.info https://*.novio.in https://*.novio.co.in https://*.easycardsloans.com 'self'
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Strengthen CSP by removing 'unsafe-eval'
- • Consider adding Permissions-Policy to control browser features
Performance Headers
1 headers
Connection
Performance
close
Caching Headers
3 headers
Age
Caching
36887
Etag
Caching
"7154b405417fef8f011ba270d1bbc9c1"
Last-Modified
Caching
Thu, 04 Dec 2025 09:38:29 GMT
Content Headers
2 headers
Content-Length
Content
4568
Content-Type
Content
text/html
Server Headers
1 headers
Server
Server
None
CORS Headers
1 headers
Access-Control-Allow-Origin
Cors
https://api.credilio.in
Cookies Headers
0 headers
No cookies headers found
Other Headers
6 headers
Alt-Svc
Other
h3=":443"; ma=86400
Date
Other
Fri, 05 Dec 2025 11:05:09 GMT
Via
Other
1.1 3203c4b5504fa019a752072f0419ef6a.cloudfront.net (CloudFront)
X-Amz-Cf-Id
Other
HbvxOOKEijRH-4LRZSpPbKkxDVGYU1e3FRRcl8GmgduCUYqDW9PrPw==
X-Amz-Cf-Pop
Other
IAD12-P3
X-Cache
Other
Hit from cloudfront
Recommendations
Enable compression (gzip/brotli) to improve performance
Add Cache-Control header to optimize caching
Analysis completed in 110ms