Open
Cached
·
just now
12
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Excellent
max-age=31536000; includeSubDomains; preload
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
2 headers
Connection
Performance
keep-alive
Keep-Alive
Performance
timeout=15
Caching Headers
1 headers
Cache-Control
Caching
max-age=3600, private
Content Headers
2 headers
Content-Length
Content
477454
Content-Type
Content
text/html;charset=UTF-8
Server Headers
1 headers
Server
Server
QRATOR
CORS Headers
0 headers
No CORS headers found
Cookies Headers
1 headers
Set-Cookie
Cookies
PHPSESSID=v5jnv1q4b1ejoqvrbapl8h22c1; path=/
Other Headers
2 headers
Content-Security-Policy-Report-Only
Other
default-src 'self' cdnweb.sbermobile.ru; frame-src https://cdn.rutarget.ru/ https://api.flocktory.com https://mc.yandex.ru https://tag.rutarget.ru/ ; style-src 'unsafe-inline' 'self' fonts.googleapis.com cdnweb.sbermobile.ru; font-src 'self' cdnweb.sbermobile.ru data: fonts.gstatic.com ; connect-src 'self' https://yandexmetrica.com:*/ *.sbermarketing.ru uaas.yandex.ru ad.adriver.ru api.flocktory.com kraken.rambler.ru https://*.mc.yandex.ru/ https://stats.g.doubleclick.net/ https://suggestions.dadata.ru/ https://suggest-maps.yandex.ru/ https://ymetrica1.com/ https://www.google-analytics.com/ https://unpkg.com/ https://stats.g.doubleclick.net/ https://mc.yandex.ru/ https://*.sberbank.ru/ https://sa.online.sberbank.ru:8098/; script-src 'self' 'unsafe-inline' 'unsafe-eval' cdnweb.sbermobile.ru *.yandex.net *.trbcdn.net top-fwz1.mail.ru api.flocktory.com *.top100.ru *.adriver.ru px.adhigh.net cdn.rutarget.ru yastatic.net *.maps.yandex.net suggest-maps.yandex.ru api-maps.yandex.ru *.otm-r.com www.google-analytics.com ajax.googleapis.com fonts.googleapis.com *.mc.yandex.ru mc.yandex.ru nlb-clickstream.sberbank.ru sp.otm-r.com stats.g.doubleclick.net www.google-analytics.com www.google.ru www.googletagmanager.com ; img-src 'self' data: www.gstatic.com cdnweb.sbermobile.ru adservings.ru api.flocktory.com top-fwz1.mail.ru kraken.rambler.ru api-maps.yandex.ru *.maps.yandex.net *.mc.yandex.com *.mc.yandex.ru mc.yandex.ru *.googleusercontent.com www.googletagmanager.com www.google.ru www.google.com www.google-analytics.com *.otm-r.com yandex.ru; base-uri 'self' cdnweb.sbermobile.ru; form-action 'self'; frame-ancestors 'none'
Date
Other
Wed, 19 Nov 2025 15:11:04 GMT
Recommendations
Enable compression (gzip/brotli) to improve performance
Analysis completed in 3180ms