Cached · 8h ago
43 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=15768000; includeSubdomains; preload;
Content-Security-Policy
Good
default-src; frame-ancestors; base-uri; +7 more
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Present
no-referrer, strict-origin-when-cross-origin
Permissions-Policy
Present
geolocation=(),midi=(),sync-xhr=(),microphone=(),camera=(),magnetometer=(),gyroscope=(),fullscreen=(self),payment=()
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Strengthen CSP by removing 'unsafe-eval'

Performance Headers

2 headers
Connection
Performance
close
Vary
Performance
Accept-Encoding

Caching Headers

2 headers
Cache-Control
Caching
s-maxage=60, stale-while-revalidate
Etag
Caching
"17eklem1kml3pso"

Content Headers

2 headers
Content-Length
Content
173766
Content-Type
Content
text/html; charset=utf-8

Server Headers

2 headers
Server
Server
nginx
X-Powered-By
Server
Next.js

CORS Headers

3 headers
Access-Control-Allow-Headers
Cors
aau-search-url, X-CSRF-Token, X-Requested-With, Accept, Accept-Version, Content-Length, Content-MD5, Content-Type, Date, X-Api-Version
Access-Control-Allow-Methods
Cors
GET,OPTIONS,POST
Access-Control-Allow-Origin
Cors
*

Cookies Headers

1 headers
Set-Cookie
Cookies
ARRAffinitySameSite=8579a052198724fbf96951d11ef28aef96e4da2387a31bad93a52f881ba0c604;Path=/;HttpOnly;SameSite=None;Secure;Domain=www.studerende.aau.dk

Other Headers

24 headers
Client-Ip
Other
[fd40:4bde:12:6e2b:7912:100:a4c:1f04]:60252
Date
Other
Wed, 24 Dec 2025 22:50:37 GMT
Disguised-Host
Other
www.studerende.aau.dk
Host
Other
www.studerende.aau.dk
Max-Forwards
Other
10
Original-Path
Other
/valg-undervejs-og-job/ivaerksaetteri-og-entreprenorskab
User-Agent
Other
mint/1.7.1
Was-Default-Hostname
Other
prod-aaudxp-website-001-app.azurewebsites.net
X-Appservice-Proto
Other
https
X-Arr-Log-Id
Other
f8d5f87f-2994-424b-ad93-fd19895bc592
X-Arr-Ssl
Other
2048|256|CN=Microsoft Azure RSA TLS Issuing CA 08, O=Microsoft Corporation, C=US|CN=*.azurewebsites.net, O=Microsoft Corporation, L=Redmond, S=WA, C=US
X-Client-Ip
Other
10.76.31.4
X-Client-Port
Other
0
X-Forwarded-For
Other
64.34.84.14, 10.76.31.4
X-Forwarded-Host
Other
www.studerende.aau.dk
X-Forwarded-Port
Other
8080
X-Forwarded-Proto
Other
https
X-Forwarded-Tlsversion
Other
1.3
X-Middleware-Rewrite
Other
/_sites/aHR0cHM6Ly93d3cuc3R1ZGVyZW5kZS5hYXUuZGs=/ISR/valg-undervejs-og-job/ivaerksaetteri-og-entreprenorskab
X-Nextjs-Cache
Other
STALE
X-Original-Url
Other
/valg-undervejs-og-job/ivaerksaetteri-og-entreprenorskab
X-Real-Ip
Other
64.34.84.14
X-Site-Deployment-Id
Other
prod-aaudxp-website-001-app
X-Waws-Unencoded-Url
Other
/valg-undervejs-og-job/ivaerksaetteri-og-entreprenorskab

Recommendations

Enable compression (gzip/brotli) to improve performance

Consider removing X-Powered-By header to hide server technology

Analysis completed in 1ms