Open
Cached
·
just now
16
Headers
Detected Technologies from Headers
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=63072000; preload
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
connection: close
Caching Headers
No caching headers found
Content Headers
Content-Length
77
content-length: 77
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Atl-Request-Id
f2affa39-8743-4908-8ac7-e3db371fcbcf
Atl-Traceid
f2affa39874349088ac7e3db371fcbcf
Date
Thu, 09 Apr 2026 07:16:58 GMT
Nel
Report-To Group
endpoint-1
max-age: 10m
failure: 1.0%
include subdomains
Server-Timing
atl-edge;dur=8149,atl-edge-internal;dur=3,atl-edge-upstream;dur=8148,atl-edge-pop;desc="aws-us-east-1"
atl-request-id: f2affa39-8743-4908-8ac7-e3db371fcbcf
atl-traceid: f2affa39874349088ac7e3db371fcbcf
date: Thu, 09 Apr 2026 07:16:58 GMT
nel: {"failure_fraction": 0.01, "include_subdomains": true, "max_age": 600, "report_to": "endpoint-1"}
report-to: {"endpoints": [{"url": "https://dz8aopenkvv6s.cloudfront.net"}], "group": "endpoint-1", "include_subdomains": true, "max_age": 600}
server-timing: atl-edge;dur=8149,atl-edge-internal;dur=3,atl-edge-upstream;dur=8148,atl-edge-pop;desc="aws-us-east-1"
via: 1.1 05f27386f4cfcb918eb11b3fea4d975e.cloudfront.net (CloudFront)
x-amz-cf-id: Tzw86vf9sbJBItVmfrejEd5t_c7m5SXIH2j6_Borj5S8_6B8xBVxTA==
x-amz-cf-pop: IAD61-P1
x-cache: Miss from cloudfront
Recommendations
Enable compression (gzip/brotli) to improve performance
Add Cache-Control header to optimize caching