Open
Cached
·
just now
15
Headers
Detected Technologies from Headers
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
no-referrer-when-downgrade
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Significantly strengthen CSP directives
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
Transfer-Encoding
chunked
Vary
rsc, next-router-state-tree, next-router-prefetch, next-router-segment-prefetch, Accept-Encoding
connection: close transfer-encoding: chunked vary: rsc, next-router-state-tree, next-router-prefetch, next-router-segment-prefetch, Accept-Encoding
Caching Headers
Age
1
Cache-Control
private, no-cache, no-store, max-age=0, must-revalidate
age: 1 cache-control: private, no-cache, no-store, max-age=0, must-revalidate
Content Headers
Content-Type
text/html; charset=utf-8
content-type: text/html; charset=utf-8
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Date
Sun, 04 Oct 2026 20:37:25 GMT
Link
Other
rel=preload
as=script
rel=preload
as=script
rel=preload
as=script
rel=preconnect
rel=preload
as=script
rel=preload
as=script
rel=preload
as=script
rel=preconnect
rel=dns-prefetch
rel=dns-prefetch
rel=dns-prefetch
rel=preload
as=font
crossorigin
rel=preload
as=font
crossorigin
rel=preload
as=style
rel=preload
as=style
date: Sun, 04 Oct 2026 20:37:25 GMT link: <https://consent.cmp.oath.com/version/7.0.2/cmp.js>; rel="preload"; as="script", <https://s.yimg.com/du/benji/benji-2.3.406.js>; rel="preload"; as="script", <https://s.yimg.com/ss/analytics3.js>; rel="preload"; as="script", <https://s.yimg.com>; rel=preconnect, <https://s.yimg.com>; rel=dns-prefetch, <https://consent.cmp.oath.com>; rel=dns-prefetch, <https://geo.yahoo.com>; rel=dns-prefetch, <https://s.yimg.com/dc/td-app-stock/fonts/YahooSansFinancial-Regular-Web.woff2>; rel=preload; as="font"; crossorigin="", <https://s.yimg.com/dc/td-app-stock/fonts/YahooSansFinancial-Semibold-Web.woff2>; rel=preload; as="font"; crossorigin="", <https://s.yimg.com/br/next-app-stock/_next/static/css/b77dae69655ab022.css>; rel=preload; as="style", <https://s.yimg.com/br/next-app-stock/_next/static/css/1e086ff7c86cd9d1.css>; rel=preload; as="style" x-envoy-upstream-service-time: 89
Recommendations
Enable compression (gzip/brotli) to improve performance