Open
Cached
·
just now
18
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Good
max-age=63072000; includeSubDomains
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Missing
Not configured
Recommendations
- • Consider adding 'preload' to HSTS for maximum security
- • Add Content-Security-Policy header to prevent XSS attacks
- • Consider adding Permissions-Policy to control browser features
Performance Headers
2 headers
Connection
Performance
close
Transfer-Encoding
Performance
chunked
Caching Headers
2 headers
Cache-Control
Caching
max-age=0, private, must-revalidate
Etag
Caching
W/"08e350b727c7b6428df18b18fad73449"
Content Headers
1 headers
Content-Type
Content
text/html; charset=utf-8
Server Headers
2 headers
X-Powered-By
Server
cloud66
X-Runtime
Server
0.006842
CORS Headers
0 headers
No CORS headers found
Cookies Headers
1 headers
Set-Cookie
Cookies
_bright_session=dLcq%2BcpHJaQ28LFDWDpOgCYlnYhKOtRYYVDaOfeLXh5fjgHqbzK8kxgdkDMVajM4AOKzFNPdThPWXMSSIya4ujutMtVvDdtMNp9unc7jogvFJ7bTCmWsPSwBkE5jxzhVD0S4PZXnVVSqnwAx24knSQ57ZPv0XGuUYA%2FGBTJIbTmWuqx%2FGg%2BLKQbsUcp1wAcuY7zaHvrF1OqI2ON9%2FL%2BIen2m2mU5X0Y8R4fXOL1Y4dvV%2FB24upmLiAMelkmIte6TDuht5S9cOFOcRnyeldtWRuswJtQ%2F0jQ%3D--erV1RUPP13reCIjb--C5Y%2BCJ2OSCsyUc4%2FxYze3Q%3D%3D; path=/; secure; HttpOnly; SameSite=Lax
Other Headers
5 headers
Date
Other
Tue, 13 Jan 2026 12:53:05 GMT
Link
Other
</assets/application-41b0588dba47e0608adc3b86ae78c5c6105832be312ec9177ec485ab954f9738.css>; rel=preload; as=style; nopush,</assets/print-91d168a594fcfec659b27d43c4f296462174c17b03abc1e6f0720a9dd5608a0c.css>; rel=preload; as=style; nopush,</assets/application-1e7a530fa81d536cc423df227d06f4d1707d3245aa735d1c4a8c912f2065da03.js>; rel=modulepreload; as=script; nopush
Status
Other
200 OK
X-Permitted-Cross-Domain-Policies
Other
none
X-Request-Id
Other
2a8a4c25-8a46-419c-a36b-f583114e55a6
Recommendations
Enable compression (gzip/brotli) to improve performance
Consider removing X-Powered-By header to hide server technology