13 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=15768000
Content-Security-Policy
Basic
default-src; base-uri; script-src; +9 more Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Improve CSP by adding more specific directives and removing 'unsafe-inline'
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

Performance Headers

Accept-Ranges
Performance
bytes
Connection
Performance
close

Caching Headers

Cache-Control
Caching
no-cache, no-store
Etag
Caching
"6a06e4f4-7a8"
Expires
Caching
Mon, 18 May 2026 15:51:08 GMT
Last-Modified
Caching
Fri, 15 May 2026 09:18:44 GMT

Content Headers

Content-Length
Content
1960
Content-Type
Content
text/html

Server Headers

No server headers found

CORS Headers

No CORS headers found

Cookies Headers

No cookies headers found

Other Headers

Cluster
Other
us
Date
Other
Mon, 18 May 2026 15:51:05 GMT
Gateway
Other
us

Recommendations

Enable compression (gzip/brotli) to improve performance