Open
Cached
·
just now
18
Headers
Detected Technologies from Headers
HTTP Security Headers
Status
Strict-Transport-Security
Good
max-age=31536000;includeSubDomains
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Missing
Not configured
Recommendations
- • Consider adding 'preload' to HSTS for maximum security
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
connection: close
Caching Headers
Cache-Control
max-age=0, no-cache, no-store
Expires
Mon, 04 May 2026 04:26:23 GMT
Pragma
no-cache
cache-control: max-age=0, no-cache, no-store expires: Mon, 04 May 2026 04:26:23 GMT pragma: no-cache
Content Headers
Content-Language
en-US
Content-Length
9369
Content-Type
text/html;charset=UTF-8
content-language: en-US content-length: 9369 content-type: text/html;charset=UTF-8
Server Headers
No server headers found
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Date
Mon, 04 May 2026 04:26:23 GMT
P3p
CP='NON DSP COR CUR ADMa OUR BUS PHY ONL COM STA PUR FIN'
Refresh
900;./index.jsp
X-Waf-Reqtraceid
0.b0813217.1777868782.d19305e5
date: Mon, 04 May 2026 04:26:23 GMT p3p: CP='NON DSP COR CUR ADMa OUR BUS PHY ONL COM STA PUR FIN' refresh: 900;./index.jsp x-waf-reqtraceid: 0.b0813217.1777868782.d19305e5
Recommendations
Enable compression (gzip/brotli) to improve performance