25 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31536000
Content-Security-Policy
Basic
base-uri; object-src; script-src; +1 more Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Present
ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*; +6 more
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Improve CSP by adding more specific directives and removing 'unsafe-inline'
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)

Performance Headers

Accept-Ranges
Performance
none
Connection
Performance
close
Transfer-Encoding
Performance
chunked
Vary
Performance
Sec-CH-Viewport-Width, Sec-CH-DPR, Device-Memory,Accept-Encoding

Caching Headers

Cache-Control
Caching
no-cache, no-store, max-age=0, must-revalidate
Expires
Caching
Mon, 01 Jan 1990 00:00:00 GMT
Pragma
Caching
no-cache

Content Headers

Content-Type
Content
text/html; charset=utf-8

Server Headers

Server
Server
ESF

CORS Headers

No CORS headers found

Cookies Headers

Set-Cookie
Cookies

Other Headers

Accept-Ch
Other
Sec-CH-Viewport-Width, Sec-CH-DPR, Device-Memory
Alt-Svc
Other
h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
Date
Other
Wed, 08 Apr 2026 15:12:09 GMT
Document-Policy
Other
include-js-call-stacks-in-crash-reports
Origin-Trial
Other
AmhMBR6zCLzDDxpW+HfpP67BqwIknWnyMOXOQGfzYswFmJe+fgaI6XZgAzcxOrzNtP7hEDsOo1jdjFnVr2IdxQ4AAAB4eyJvcmlnaW4iOiJodHRwczovL3lvdXR1YmUuY29tOjQ0MyIsImZlYXR1cmUiOiJXZWJWaWV3WFJlcXVlc3RlZFdpdGhEZXByZWNhdGlvbiIsImV4cGlyeSI6MTc1ODA2NzE5OSwiaXNTdWJkb21haW4iOnRydWV9, AiDEBptUfVeO93q48VdVMe/ubupazdAl8AaHP+NBzdnW8quUcHdzJUyGSfrmtpKJu7EOvwRp9ug2rEo3XU+WMAMAAAB2eyJvcmlnaW4iOiJodHRwczovL3lvdXR1YmUuY29tOjQ0MyIsImZlYXR1cmUiOiJEZXZpY2VCb3VuZFNlc3Npb25DcmVkZW50aWFsczIiLCJleHBpcnkiOjE3NzQzMTA0MDAsImlzU3ViZG9tYWluIjp0cnVlfQ==
P3p
Other
CP="This is not a P3P policy! See http://support.google.com/accounts/answer/151657?hl=en for more info."
Report-To
Other
Group youtube_main max-age: 4w
Reporting-Endpoints
Other
crash-reporting="/web-reports?context=eJwVzX9I3HUcx_F9fdISr_Pu-_38il3kcFI0OztFjW3IhpSMhSaMwZgLmT-Wgp6X3l2ejW0MHXNbIzfHWFk4iHJLZZVJJlZQpNamthGoZIVQoolR1jRW2Lc_HvDizYvXO2XggVh22MrYG7YOP95oPTvZZJ0vilr33olafcNRa3lr3CpLj1t1PzZbb_kPJjVvOZg0fCiFxG8plGV6uLvPw3KJh8F3PQx_4GFuwUNu7CEWS72MXPVyZN5Lz1AqpaOpdLhW_k0lv8BHvNqHJ-7j9XYf2Vd8mK99tM_7GMnwc-cNP9-v-bmQZ9N1wGau3Kb4RZtjx2xaXYUXbD67YRPot3lk0WZ-3aZlp8NskcPGPofiMoeFBoeCCYc9kw677jgkPygoDgjeSxME8wRH9wjWnxekNAjaGgU_nxQcviygVzDyoaDyY0HRtGD1F0HnH4J_7gvOSUmpkXifllREJQeuSo67PnX1d0um3pYkeiVLw5LlUUn4lmRoSvLrt5KeaUn9rCSyIOn8XdK8Lnlzk-IZrdj2sGIyoEikKdq2KZoeU-RsV4xlKq6FFIX7FddPK94_q7AuK1a-UtSMKTaPK27fVkRmFEP_m3XvPyg6Vtzuqru1oVCbNGe8mk9szS7hZqWpCmjOZWruP6V54TlNconmtUrN9hrNrTrN6Yhmd1TzRUzzSkJTd0LTc0pT0Kop7NA8eUXzUo_m1X7NpY80aYOae19q1r7TXJzR9M1qyhbd_Jcm8Lf7O8nwp2st2RD3Gpa0YecWQ5fr0XRDVoahxfX5E4aNTMPZHYZIqWHAtbbfkKg3tEcM3xw3dJ8wdJ43OJ7k8Z9mJjb7b3bdNenBREMsGquoznq5uiJ4tLEhHA1Wh6uClY210drKI3XlOaGc_FBuKD8rtKM8EvoPag3Z3g"

Recommendations

Enable compression (gzip/brotli) to improve performance