Open
Cached
·
just now
18
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Consider adding Permissions-Policy to control browser features
Performance Headers
1 headers
Connection
Performance
close
Caching Headers
2 headers
Cache-Control
Caching
max-age=0, private, must-revalidate
Etag
Caching
W/"2c38956d5b8e11562302537f64c166e7"
Content Headers
2 headers
Content-Length
Content
43823
Content-Type
Content
text/html; charset=utf-8
Server Headers
2 headers
Server
Server
nginx/1.18.0
X-Runtime
Server
1.216753
CORS Headers
0 headers
No CORS headers found
Cookies Headers
1 headers
Set-Cookie
Cookies
_DreamIn_session=4VGMges0J%2BeKGXU%2BHWjdC%2BqEH%2B%2FCqE71DysGf4U3vCCcamdZ59QPpLFHOABlqvnh%2BG%2BkgcOPBLbhz%2FWiNVdDYOv84lX9hJTp4M5TpwhwvjRU0kv8I1Y%2FEC4zHS928Vh%2FiYvFB%2B%2BO5htOTILvzHBJeJ2EM5QpSlMxPl54jPwtUiutor6xxRXy1mc9xU6cKR3lCwRcoWVZtkKam3DClJW0TJSPkFaN6M4PpiFagoPfGafAb2Ny0aYcDR7vz%2B72IFPAXXxqA%2BuuVGrniWUniz3zTI8qeNayK4TG6czTOUafCEAuMfKeDTAmErSuVIb8TxYnb%2BqPFfxlwohc6xdoE7Vd054Yic0eVK8e--AnKe6RVW0jj7wAjt--te3QETbMtt8j9jax%2BgYWhw%3D%3D; domain=.synergy-munich.de; path=/; HttpOnly; SameSite=Lax
Other Headers
6 headers
Date
Other
Tue, 23 Dec 2025 08:52:42 GMT
Link
Other
</assets/application-9c1f3abf5fa3be82aa6df40cf5cff97af4a2fad7aabf888af1495abb3b4e84f0.css>; rel=preload; as=style; nopush,</assets/independent_pages/external_synergy/external_synergy-d382583bdfad16893354753088db0587c74b3b33d066d273ae9aa60328462075.css>; rel=preload; as=style; nopush,</assets/application-6dd62194c1d61c5d53100be83831a08afcba895a593084d2a4d6a19101e1d7b0.js>; rel=preload; as=script; nopush,</packs/js/main_pack-331801b2b481e1145de1.js>; rel=preload; as=script; nopush,</packs/css/main_pack-f6c54ad2.css>; rel=preload; as=style; nopush
X-Download-Options
Other
noopen
X-Permitted-Cross-Domain-Policies
Other
none
X-Request-Id
Other
3e053ef6-3339-4c59-bfad-49ed66f819b8
X-Robots-Tag
Other
noindex
Recommendations
Enable compression (gzip/brotli) to improve performance
Analysis completed in 2168ms