Open
Cached
·
just now
18
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000
Content-Security-Policy
Basic
frame-ancestors; default-src; script-src; +8 more
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
no-referrer-when-downgrade
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Consider adding Permissions-Policy to control browser features
Performance Headers
3 headers
Connection
Performance
keep-alive
Transfer-Encoding
Performance
chunked
Vary
Performance
Accept-Encoding
Caching Headers
2 headers
Age
Caching
0
Cache-Control
Caching
private
Content Headers
1 headers
Content-Type
Content
text/html; charset=UTF-8
Server Headers
1 headers
Server
Server
ATS
CORS Headers
0 headers
No CORS headers found
Cookies Headers
1 headers
Set-Cookie
Cookies
PROMO=ono_sc=1&ono_fts=1762880497<v_pid=<v_new=1<v_ts=1762880497<v_sts=1762880497<v_c=1; expires=Wed, 11-Nov-2026 17:01:37 GMT; Max-Age=31536000; path=/; domain=.search.yahoo.com
Other Headers
4 headers
Date
Other
Tue, 11 Nov 2025 17:01:37 GMT
P3p
Other
policyref="https://policies.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Secure_search_bypass
Other
true
X-Envoy-Upstream-Service-Time
Other
27
Recommendations
Enable compression (gzip/brotli) to improve performance
Analysis completed in 341ms