Open
Cached
·
just now
37
Headers
Detected Technologies from Headers
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
Transfer-Encoding
chunked
Vary
Accept-Encoding
connection: close transfer-encoding: chunked vary: Accept-Encoding
Caching Headers
Age
60
Cache-Control
public,max-age=15
age: 60 cache-control: public,max-age=15
Content Headers
Content-Type
text/html; charset=utf-8
content-type: text/html; charset=utf-8
Server Headers
server: cloudflare x-powered-by: Express
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
0
C
1
o
10
c
11
u
12
r
13
i
14
t
15
y
16
-
17
P
18
o
19
l
2
n
20
i
21
c
22
y
3
t
4
e
5
n
6
t
7
-
8
S
9
e
Date
Thu, 02 Apr 2026 16:38:23 GMT
Link
rel=preload
as=script
0: C 1: o 10: c 11: u 12: r 13: i 14: t 15: y 16: - 17: P 18: o 19: l 2: n 20: i 21: c 22: y 3: t 4: e 5: n 6: t 7: - 8: S 9: e cf-cache-status: HIT cf-ray: 9e61437e3e9cd62d-IAD date: Thu, 02 Apr 2026 16:38:23 GMT link: <https://assets.prothomalo.com/prothomalo/assets/app-8331ce3ea9067f4a09b9.js>; rel=preload; as=script;
Recommendations
Enable compression (gzip/brotli) to improve performance
Consider removing X-Powered-By header to hide server technology