Open
Cached
·
5h ago
16
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000
Content-Security-Policy
Good
default-src; style-src; frame-src; +2 more
default-src 'self' data: blob: stg.essentials.transferpricing.pwc.com stg.identity.transferpricing.pwc.com stg.reportingsuite.transferpricing.pwc.com reportingsuite.transferpricing.pwc.com tpi.pwcinternal.com tpi-stg.pwcinternal.com login-stg.pwc.com login-stg.pwcinternal.com login.pwc.com dc.services.visualstudio.com; style-src 'self' 'sha256-47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=' 'sha256-RPi6qkZFJreHgYBe3yjPOjai7ouMAknFLPlgUZFW0vE=' 'sha256-R3PuhrOQcvVsMiQURwTTFtp4yWhdKVPE9Kw5x4qP0kE=' 'sha256-KGlQ2/0pOli8Z/KZbjyw6TdwFCOHWwjaxUd6zX3E1rw=' 'sha256-BSQBnFbMcI3Va0Fvxp2n2DmSubVX7gCJP69gqxbKkBQ=' 'sha256-SmSNjobIkBILzA7MZxkWDc5rVR8DinCzhR6mmZmOI3A=' 'sha256-AxV899TmSOju5BFfShEKvPeyKuxmvTbc1sFp7a+gSHY=' 'sha256-95A+bHpuyItNVG+fsP+BqEFZfWHO11BlMHg8SEcYl24=' 'sha256-hWkC9Cxr16xod+LYvYTyTecvzy6g0R364S9MpfSkKHU=' 'sha256-/lXNXWRTvRx1QM5MfevNc0yGVnLxD92WQldG38oh04k=' 'sha256-KPnrTsVdmsQWUxtWmGcRrru87M28z10WMt5YLLX1xwM=' 'sha256-y4ApDNEI6jOxYk+NAdQikSG+IHkdMh5NUUI1N0hHp/4=' 'sha256-S6z1fdJ2CvMSHbhZ4E2KgkEViZh21TmOA5pwYCkcUNA=' 'sha256-StpIoD4mRLsd6l+dhtiqNTTxbEvBKcz/O1Y24o4ICAA=' 'sha256-Hs5JMzEGHFbAUrPORzBORYQjnzhBz0BCsrAA2HPfcZI=' 'sha256-hBwLf1G1zgqrIkALAGXPRY3dJfnDDcmKtcO4MI8hA6c=' 'sha256-kSHw3nRoLIj/Bgjc7vwSJFI80kkKsbZOFl04UpJoI6E=' 'sha256-0Hml6reBuNkD6WjZCAjDAmiynY1a38LqUGFMmMIDNcE=' 'sha256-YMfR1fzvNkwW8ldr9D9oniEBTN8bGOmSSoNODogR2zY=' 'sha256-HYSUN8YvoWcBzINkT9kVZOboNhq4kqp7qhV9O3mf3Ds=' 'sha256-WYhK35QvNjpRhrME89uGnqX1d5a+lbtJjuAXk/8e4os=' 'sha256-6HtrjxvE3U8hTG5BT+xLiiaoKhwSn4z3F0WwMPTW5c8=' 'sha256-v+nu3/1WVjFAtcEbVAuaQ/LM1f9aGq4/R1pMBmlrHR8=' 'sha256-iMuY56wGfdInxuLEkfHUb+W/aUS/luzNYmd9e5+BEaQ=' 'sha256-qdCRoZdyDtrkj8b+i8HKFvLX2G5Z2e6PT/qfpm06YoE=' 'sha256-powvk+SB13BxYIGLl6uFoOTpG7iJHg5L1HAYOh772U4=' 'sha256-HuqmzeLxIwJcnfrJ5QgNqUUISmrMnrBpadBGE5Wx+jo=' 'sha256-acxYi/gTs6YEIzBuLf2iNJfz5H8syIiZta/qihrUF5Q=' 'sha256-Js+lWW7pADP/ip/7tgibT+wJLbNsjhEGr+iSxkGk+Mc=' 'sha256-ue9MoYxX6rmuaoYAZd3JioK4rzU3oeqPY96c9es6+GE=' 'sha256-ohUqtquDg9y2GFv6uHd0N3+rBaFtTikax7mlqulHkGk=' 'sha256-UFVl3EWJUkDE2jVW+bg02ryz1WyGfdkIAeIvOait0jQ=' 'sha256-W+b4lHEpYmzvM2oZNUM0LSGI7b0whv5Mg+6E78jUDiw=' 'sha256-KgWNJOmn4Oi27ovtORhDtlPgC7kWZzbrwuMGZEk+ilM=' 'sha256-p7PVb3j3AnS4BsubP/WdqrEfKcRI+KnfUMy2Q9+TFmg=' 'sha256-0vUW22lLhmdUTT/dUOphlBuOYaHGQDH9tHs3De3H9R4=' 'sha256-nJGl58laEfLV/4xUbIE3zhrbXOX0DSO/TMlHvPIRQpQ=' 'sha256-fxmIdYwubRq5JGHrHduS6QHQU+IUdQjqLuwGiNi2+cg=' 'sha256-45T2C7l9Cu/wXSVCXfR0uCMbb5KEZCBPCXDZ3U9M9qg=' 'sha256-ol5bUqKE/nuA1mNRtDvMb4TZbq2/51SP+qERy0potqA=' 'sha256-bgVIOGTqaVAq4Ql/siNoGnt6HpldB5PoY+Kydi/CrmU=' 'sha256-xVUzgaU67H8iXYLftbqZlKkRieHq+L3wFoRjTh5ZMeU=' 'sha256-4l0q5Fi08/ZUlUwIBY6yYGfeV6c2EXi0wtnw7RuhXaA='; frame-src 'self' *.pwc.com *.pwcinternal.com; frame-ancestors 'self' *.pwc.com *.pwcinternal.com; report-uri /api/cspreport
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Strengthen CSP by removing 'unsafe-eval'
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
3 headers
Accept-Ranges
Performance
bytes
Connection
Performance
close
Transfer-Encoding
Performance
chunked
Caching Headers
3 headers
Cache-Control
Caching
no-store, must-revalidate, no-cache, max-age=0, s-maxage=0
Etag
Caching
"1dc6e9c32c50f4c"
Last-Modified
Caching
Tue, 16 Dec 2025 14:56:46 GMT
Content Headers
1 headers
Content-Type
Content
text/html
Server Headers
1 headers
X-Powered-By
Server
ASP.NET
CORS Headers
0 headers
No CORS headers found
Cookies Headers
1 headers
Set-Cookie
Cookies
incap_ses_1307_2614003=WLR4cHy/BEkK75EFGGYjEg2ASmkAAAAAXksYgRXRkgF6zcPxB8vrTA==; path=/; Secure; SameSite=None
Other Headers
4 headers
Date
Other
Tue, 23 Dec 2025 11:42:06 GMT
Request-Context
Other
appId=cid-v1:ec7c668c-f6b5-4fd4-94f2-e061e70451ea
X-Cdn
Other
Imperva
X-Iinfo
Other
4-19246223-19246226 NNNN CT(86 188 0) RT(1766490126542 7) q(0 0 2 0) r(3 3) U12
Recommendations
Enable compression (gzip/brotli) to improve performance
Consider removing X-Powered-By header to hide server technology
Analysis completed in 0ms