Open
Cached
·
just now
29
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains
Content-Security-Policy
Good
base-uri; default-src; frame-ancestors; +9 more
base-uri 'none';default-src 'none';frame-ancestors https://support.code.dev-theguardian.com;style-src 'unsafe-inline';script-src profile.code.dev-theguardian.com www.google.com www.gstatic.com assets.guim.co.uk;img-src profile.code.dev-theguardian.com static.guim.co.uk ophan.theguardian.com www.google.com;font-src assets.guim.co.uk;connect-src 'self' consent-logs.code.dev-guardianapis.com api.nextgen.guardianapps.co.uk https://api.pwnedpasswords.com idapi.code.dev-theguardian.com www.google.com ophan.theguardian.com;frame-src www.google.com;object-src 'none';script-src-attr 'none';upgrade-insecure-requests
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
no-referrer
Permissions-Policy
Missing
Not configured
Recommendations
- • Consider adding 'preload' to HSTS for maximum security
- • Strengthen CSP by removing 'unsafe-eval'
- • Consider adding Permissions-Policy to control browser features
Performance Headers
3 headers
Accept-Ranges
Performance
bytes
Connection
Performance
close
Vary
Performance
Accept-Encoding
Caching Headers
3 headers
Cache-Control
Caching
no-store
Etag
Caching
W/"91e5-/d+PMlQL1IpYMX3EizIgOFw+idM"
Pragma
Caching
no-cache
Content Headers
2 headers
Content-Length
Content
37349
Content-Type
Content
text/html; charset=utf-8
Server Headers
0 headers
No server headers found
CORS Headers
0 headers
No CORS headers found
Cookies Headers
1 headers
Set-Cookie
Cookies
GU_mvt_id=657280;path=/;expires=Mon, 30 Mar 2026 11:00:21 GMT;domain=.code.dev-theguardian.com;Secure;SameSite=Lax
Other Headers
12 headers
Date
Other
Tue, 30 Dec 2025 11:00:21 GMT
Origin-Agent-Cluster
Other
?1
Via
Other
1.1 varnish
X-Cache
Other
MISS
X-Cache-Hits
Other
0
X-Dns-Prefetch-Control
Other
off
X-Download-Options
Other
noopen
X-Gu-Geolocation
Other
US
X-Gu-Geolocation-State
Other
VA
X-Permitted-Cross-Domain-Policies
Other
none
X-Served-By
Other
cache-iad-kiad7000154-IAD
X-Timer
Other
S1767092421.471363,VS0,VE466
Recommendations
Enable compression (gzip/brotli) to improve performance