Cached · just now
24 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Excellent
max-age=31536000; includeSubDomains; preload
Content-Security-Policy
Basic
default-src; script-src; style-src; +11 more Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Present
strict-origin-when-cross-origin, no-referrer
Permissions-Policy
Present
fullscreen=(self "https://www.youtube.com" "https://cdn.iframe.ly"), picture-in-picture=(self "https://www.youtube.com" "https://cdn.iframe.ly"), encrypted-media=(self "https://www.youtube.com" "https://cdn.iframe.ly")
Recommendations
  • Improve CSP by adding more specific directives and removing 'unsafe-inline'

Performance Headers

Accept-Ranges
Performance
bytes
Connection
Performance
close
Transfer-Encoding
Performance
chunked
Vary
Performance
Origin, Accept-Encoding

Caching Headers

Age
Caching
25745
Cache-Control
Caching
max-age=3600, must-revalidate, public, s-maxage=604800
Etag
Caching
W/"e32b13a7edbe2708"
Last-Modified
Caching
Mon, 23 Feb 2026 13:28:43 GMT

Content Headers

Content-Type
Content
text/html; charset=UTF-8

Server Headers

No server headers found

CORS Headers

No CORS headers found

Cookies Headers

No cookies headers found

Other Headers

Date
Other
Mon, 23 Feb 2026 20:38:10 GMT
Traceresponse
Other
00-1896faa52ade185fb34122f8e7a0cba8-16be610114955650-01
Via
Other
1.1 varnish.0 (Varnish/7.3)
X-Cache
Other
HIT
X-Debug-Info
Other
eyJyZXRyaWVzIjowfQ==
X-Platform-Cluster
Other
hyndwxcuxfgsc-main-bvxea6i
X-Platform-Processor
Other
khmeoy6upeaipik5haola5g4wu
X-Platform-Router
Other
ofgfu4mstufjtzrio2diyoqu7q
X-Varnish
Other
75304039 42433392

Recommendations

Enable compression (gzip/brotli) to improve performance