Open
Cached
·
just now
21
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Excellent
max-age=63072000; includeSubDomains; preload
Content-Security-Policy
Basic
frame-ancestors; base-uri; default-src; +11 more
frame-ancestors 'self' https://app.kontent.ai https://www.sonarsource.com; base-uri 'self'; default-src data: 'unsafe-inline' 'unsafe-eval' https:; style-src data: 'unsafe-inline' https:; img-src data: https: blob:; font-src data: https:; connect-src https: wss: blob:; media-src https: blob:; object-src; child-src https: data: blob:; form-action 'self' https:; block-all-mixed-content; script-src 'nonce-bDhfYo4xPI4tNgoYUWL/MB1LO9kEMBNy' 'unsafe-eval' 'strict-dynamic' 'unsafe-inline' 'self' https: http:; report-uri /.netlify/functions/__csp-violations
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Present
geolocation=*, camera=()
Recommendations
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
Performance Headers
3 headers
Accept-Ranges
Performance
bytes
Transfer-Encoding
Performance
chunked
Vary
Performance
Accept-Encoding
Caching Headers
3 headers
Age
Caching
8404
Cache-Control
Caching
public,max-age=0,must-revalidate
Etag
Caching
"0eacfa847bd233cdbce0f576a3253ad5-ssl-df"
Content Headers
1 headers
Content-Type
Content
text/html; charset=UTF-8
Server Headers
1 headers
Server
Server
Netlify
CORS Headers
1 headers
Access-Control-Allow-Origin
Cors
*
Cookies Headers
1 headers
Set-Cookie
Cookies
LeadSourceNewCookie=%7B%22lead_category%22%3A%22Direct%22%2C%22lead_source%22%3A%22Direct%20Web%22%2C%22entry_url_path%22%3A%22%2Fproducts%2Fsonarcloud%2F%22%7D; Path=/; Expires=Tue, 20 Jan 2026 22:26:40 GMT
Other Headers
4 headers
Cache-Status
Other
"Netlify Edge"; hit
Date
Other
Fri, 21 Nov 2025 22:26:40 GMT
X-Debug-Csp-Nonce
Other
invoked
X-Nf-Request-Id
Other
01KAM8DN9M7XW0W34C4MD3VC01
Recommendations
Enable compression (gzip/brotli) to improve performance
Analysis completed in 564ms