Open
Cached
·
just now
20
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Consider adding Permissions-Policy to control browser features
Performance Headers
2 headers
Connection
Performance
close
Transfer-Encoding
Performance
chunked
Caching Headers
2 headers
Cache-Control
Caching
max-age=0, private, must-revalidate
Etag
Caching
W/"52aa3fd53242824644fa9f08e5e75c9d"
Content Headers
1 headers
Content-Type
Content
text/html; charset=utf-8
Server Headers
1 headers
X-Runtime
Server
0.016902
CORS Headers
0 headers
No CORS headers found
Cookies Headers
1 headers
Set-Cookie
Cookies
_session_id=0feb5aeb594d90c1d45c3e781a0ac67c; path=/; expires=Sun, 18 Jan 2026 16:31:59 GMT; secure; HttpOnly
Other Headers
9 headers
Date
Other
Sun, 18 Jan 2026 04:31:59 GMT
Link
Other
</assets/users_sign_in-30e194035181cfe5dcdf76712a8e705c5a28c5981d95ea8531e27ac0267896de.css>; rel=preload; as=style; nopush
Via
Other
1.1 cabb72a15b7245bc705e8a8014876486.cloudfront.net (CloudFront)
X-Amz-Cf-Id
Other
Tx_nGLmnt38cH86s0svFrNVClo-zkWFLgo1jvu-88_JNH-rqtlx6pA==
X-Amz-Cf-Pop
Other
MCI50-P2
X-Cache
Other
Miss from cloudfront
X-Download-Options
Other
noopen
X-Permitted-Cross-Domain-Policies
Other
none
X-Request-Id
Other
429f7ba6-a82a-4795-9905-62cec187ab21
Recommendations
Enable compression (gzip/brotli) to improve performance