Open
Cached
·
just now
56
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000
Content-Security-Policy
Good
default-src; script-src; style-src; +10 more
default-src 'self';script-src 'self' https://subscriptions.payments.yahoo.com https://cdn.payments.yahoo.com https://s.yimg.com/ https://ec.yimg.com/didomi/ 'nonce-MWMwYjQ1YzEtYjVkNS00YjlkLWIyYWQtZjA5ZDMyNTExNmUz' 'sha256-GAjmaehDsJH2jDoKMtZaYsCWJI2Ugs8esNnVYk0k3f0=' 'sha256-oxle7j3cID7IXumE4HYP0msjVTXOYty6vFuJOD4W/GI=';style-src self 'unsafe-inline' https://cdn.payments.yahoo.com https://subscriptions.payments.yahoo.com;connect-src 'self' https://guce.yahoo.com https://subscriptions.payments.yahoo.com https://cdn.payments.yahoo.com https://udc.yahoo.com https://consent.yahoo.com/ https://api.alyavista.com https://acapi.yahoo.com https://api.privacy-center.org/ https://sdk.privacy-center.org/ https://s.yimg.com/oa/consent.js.map https://geo.yahoo.com https://datacollector.payments.yahoo.com;img-src 'self' https://cdn.payments.yahoo.com https://subscriptions.payments.yahoo.com https://s.yimg.com https://ganon.yahoo.com/ https://geo.yahoo.com/;font-src 'self' https://subscriptions.payments.yahoo.com https://cdn.payments.yahoo.com https://s.yimg.com https://consent.yahoo.com/ https://guce.engadget.com;frame-src 'self' https://consent.yahoo.com/ https://ganon.yahoo.com/ https://geo.yahoo.com/ https://guce.engadget.com;object-src 'none';base-uri 'self';form-action 'self';frame-ancestors 'self';upgrade-insecure-requests ;media-src 'self' https://cdn.payments.yahoo.com;
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Present
geolocation=(self), camera=(), microphone=(), fullscreen=(), payment=(self)
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Strengthen CSP by removing 'unsafe-eval'
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
Performance Headers
3 headers
Connection
Performance
close
Transfer-Encoding
Performance
chunked
Vary
Performance
RSC, Next-Router-State-Tree, Next-Router-Prefetch, Next-Router-Segment-Prefetch, Accept-Encoding
Caching Headers
2 headers
Age
Caching
0
Cache-Control
Caching
private, max-age=0, must-revalidate
Content Headers
1 headers
Content-Type
Content
text/html; charset=utf-8
Server Headers
1 headers
Server
Server
ATS
CORS Headers
3 headers
Access-Control-Allow-Credentials
Cors
true
Access-Control-Allow-Headers
Cors
Authorization, Client-Name, Country, Currency, Content-Type, RequestId
Access-Control-Allow-Methods
Cors
GET, POST, OPTIONS, PUT
Cookies Headers
0 headers
No cookies headers found
Other Headers
39 headers
X-Forwarded-Proto
Other
https
X-Cdn
Other
YCPI-frontpage
X-Forwarded-For
Other
64.34.84.14, 69.147.94.190
X-Yahoo-Dc-Robot
Other
1
X-Acookie-Fields
Other
BBX=0; GUC=0; A1=0; A3=0; MISMATCH=0; C_WOEID=23424977; S_WOEID=2347591; IS_EU=0; GEN_EXEMPT=1; G_TOS=UNK;
Date
Other
Fri, 05 Dec 2025 07:01:40 GMT
X-Amzn-Trace-Id
Other
Root=1-69328354-782cc84745e3d8c87b7cb178
X-Forwarded-Host
Other
www.yahoo.com
X-Ja3-Via
Other
e26.ycpi.dca.yahoo.com
X-Safet-Matched-Rules
Other
global.remote_ip;orm=0;orc=0;
X-Amzn-Mtls-Clientcert-Issuer
Other
CN=Yahoo Athenz CA,OU=BF,O=Yahoo,C=US
X-Forwarded-Port
Other
443
X-Yahoo-Dc-Time-Cost
Other
2
X-Guce-Trap-Fields
Other
CLIENT=NONEU;
X-Yahoo-Dc-Device-Type
Other
featurephone
X-Envoy-Upstream-Service-Time
Other
12
X-Envoy-Expected-Rq-Timeout-Ms
Other
15000
X-Yahoo-Dc-Classify-Method
Other
use global default type
X-Amzn-Mtls-Clientcert-Serial-Number
Other
4741653555B6BEEE558AF8999EF46E0E
Link
Other
<https://s.yimg.com/bw/fonts/yahoo-product-sans-vf.woff2>; rel=preload; as="font"; crossorigin=""; type="font/woff2", <https://s.yimg.com/cv/apiv2/finance/fonts/GT-America-Standard-Medium.woff2>; rel=preload; as="font"; crossorigin=""; type="font/woff2"; fetchpriority="high"
Client-Ip
Other
64.34.84.14
Y-P
Other
eyJhbGciOiJFQ0RILUVTK0ExMjhLVyIsImVuYyI6IkExMjhDQkMtSFMyNTYiLCJlcGsiOnsiY3J2IjoiUC0yNTYiLCJrdHkiOiJFQyIsIngiOiJpUndPLUtSSVhPOXdUYVZDY2lJZFZldG0xSE5sU2pBdTZUaUtrRWcyeTJZIiwieSI6Im9fXzk2UkJxTEdlQVZlWGZmVE5FTUlTcjJOdk5mUUpnYWtxeW9pOXQ0Sk0ifSwia2lkIjoiMCIsInR5cCI6IkpXVCJ9.4jlantC0dPbUhU7AeqQGVyq91v7C7wgRg1HCkBA8LpZ8C77ZSF422g.gWVWLdTYRre3amFmJy4WpQ.l8acOb94kwth9_2Jx8nUsgMCs1Qsfat08H4VnyXXOjzR97Qq9Z_Ldr6kPiZX0t0qnZ1xRva64ZTFxsWcRSQ29lPsrJkzY0lL4Zlz70aTAMFWD555EVRkjPF8T8VItdKcbYLGAtCHdxWhTx3CqPJwuKERKOD213VM6y1KsZWV4G0QS1MV9Y1Hpr6jYOdgKhnAuexAZWPkPIm89CeQJoSA0w4c7c_I00TuxyEcFRNGnWbjQadIPYpEEVZchxhTVtrn_fkvpOLKtGWbwrZnBqW3w6RAJw60EC8iaDTa5S-9_ECtTrKVUvkCmbFm-ReAT3b03MkD-MY9ucusrlYephcD4AmzzjLmx0tao_sAcpdyzVY0BUoENrsnpEWTh4dIZSYlJmdvcG8SaTQJZm_Q1rgHSAnWbx1v2apgCXmblNwL3OAIXNRicoz6lB29lU9XxXsrBOi8mp11SbCzj1FRZ14r46zs5b47kvZeK6gYurZ_c2-Ij93p9A4CUKuaDsfLjmBixEI6CTojTbRrfcsdHFg9BjlX0hRhPbV4hLRPBXDt8m8Nh0NCnbXIrXRRSlWabJ_8RENoAvzmLO6aX7rX5MoVosEQij_lH-Bd1UTgj_Bx_cazsaGshxgJxvmz3_xZcyLHzWIDkT7H5O_oHZqL5El6OSoVOjTureby6WGxjvLcNBInlsQg4cCnce92lujSlhQ679c1UfpByIcWsZlnaGN30eE11G9WyENPr5pMPWi24SY_Z_odIa_wPl7CtTKfEOopbOh5x0TYT4yT__vx3N5icl_jm4PP9qbNrJXLmc3hqfi8mYEYm5-nOJoNFYfiQ5oZy9gNOBuVlLNeCJ2oGNbbCqTLcN-EjQYvU-yawmIgZ_1s-HotsPj1wW7DKZnOLbdiuJfO2fnP9NAPZbih6wqWAqZiFBs3RTpZODW0McvjCho.RwowMqS1Nv1zSIOcT96bbg
X-Yahoo-Site
Other
frontpage
X-Request-Id
Other
dae0eadb-8e1c-4cc4-a846-bfef45ca8535
Chad
Other
aig;
X-Amzn-Mtls-Clientcert-Leaf
Other
-----BEGIN%20CERTIFICATE-----%0AMIIECDCCA46gAwIBAgIQR0FlNVW2vu5ViviZnvRuDjAKBggqhkjOPQQDAzBEMQsw%0ACQYDVQQGEwJVUzEOMAwGA1UEChMFWWFob28xCzAJBgNVBAsTAkJGMRgwFgYDVQQD%0AEw9ZYWhvbyBBdGhlbnogQ0EwHhcNMjUxMjA0MjExMzU4WhcNMjYwMTAzMjIxMzU4%0AWjCBhzELMAkGA1UEBhMCVVMxCzAJBgNVBAgTAkNBMRIwEAYDVQQHEwlTdW5ueXZh%0AbGUxDzANBgNVBAoTBkF0aGVuejElMCMGA1UECxMcc3lzLm9wZW5zdGFjay5wcm92%0AaWRlci15YmlpcDEfMB0GA1UEAxMWeWNwaS5lZ3Jlc3MueWNwaS1yZW1hcDCCASIw%0ADQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMeVi9IJS/Bg2PXbY4QW2NkodSq1%0AGurlC0zlgrD45SaLhsnLV+G/QjMp/rs66miNJRnvyEWl3ko/0v7R/ANxSRONrDgf%0AaJLa0EfVaXX71PAs2MhBdVPFAhYertzUAV3Hl34bpzTqgYo0kFcFbdBuOs6vwHoN%0AvLBjbJN0VmUI0cawYsSKH/sGxv9hA1wowGWpbMWWDF7I8doUww3em7UQkhW5PII8%0AqjbB/N6nkDvWr8xnV+7+9wmoTYvaMCp9vVhmdX2Gz7XMFTCg8jotyRoY1L8d7Z6A%0ASD704LP+BgUErLx2msLrHrmG1Ch45yKlnfaXiDMMOuyatTdg50XUUlEjwnECAwEA%0AAaOCAVEwggFNMA4GA1UdDwEB/wQEAwIFoDAMBgNVHRMBAf8EAjAAMB8GA1UdIwQY%0AMBaAFE3dgX+Akgvzzv9jIsRzbjFHl71eMIHsBgNVHREEgeQwgeGCJ3ljcGktcmVt%0AYXAueWNwaS1lZ3Jlc3MueWJpaXAub2F0aC5jbG91ZIcERZNevocQIAFJmAAUCAoA%0AAAAAAAAwAIY6c3BpZmZlOi8vYXRoZW56LmNsb3VkL25zL2RlZmF1bHQvc2EveWNw%0AaS5lZ3Jlc3MueWNwaS1yZW1hcIY4YXRoZW56Oi8vaW5zdGFuY2VpZC9zeXMub3Bl%0AbnN0YWNrLnByb3ZpZGVyLXliaWlwLzUyNDIwODOGKGF0aGVuejovL2hvc3RuYW1l%0AL2UyNi55Y3BpLmRjYS55YWhvby5jb20wHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsG%0AAQUFBwMCMAoGCCqGSM49BAMDA2gAMGUCMQDY+V+eHMu/UZFSG/XgNlFxJsSviMqX%0Ao7DeG+8342ecBahFehMJYkDVOs2wB85z9ioCMEcEqLEztH2kPsz/rndepAqElmoM%0A39DIIwE+WVAUytUisdEJnAx77zaiztJ4cxVjOQ==%0A-----END%20CERTIFICATE-----%0A
X-Yahoo-Lang
Other
en-US
X-Amzn-Mtls-Clientcert-Validity
Other
NotBefore=2025-12-04T21:13:58Z;NotAfter=2026-01-03T22:13:58Z
User-Agent
Other
mint/1.7.1
X-Ja3-Sig
Other
82569576b8b454070ce9cb583993367a
X-Jaws
Other
56-782000000000073807ff00fffffb19ff|7-e4000000680|6-5f
X-Consent-Flow
Other
yguce
X-Safet-Classification
Other
GOOD
X-Yahoo-Region
Other
US
X-Amzn-Mtls-Clientcert-Subject
Other
CN=ycpi.egress.ycpi-remap,OU=sys.openstack.provider-ybiip,O=Athenz,L=Sunnyvale,ST=CA,C=US
X-Ycpi
Other
1
X-Jaws-Via
Other
e26.ycpi.dca.yahoo.com
X-Jurisdiction-Type
Other
US
Host
Other
www.yahoo.com
Recommendations
Enable compression (gzip/brotli) to improve performance
Analysis completed in 407ms