13 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains;
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Consider adding 'preload' to HSTS for maximum security
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

Performance Headers

2 headers
Accept-Ranges
Performance
bytes
Vary
Performance
Accept-Encoding

Caching Headers

3 headers
Cache-Control
Caching
no-cache
Last-Modified
Caching
Thu, 06 Nov 2025 03:37:06 GMT
Pragma
Caching
no-cache

Content Headers

2 headers
Content-Length
Content
108769
Content-Type
Content
text/html; charset=utf-8

Server Headers

1 headers
Server
Server
Apache

CORS Headers

0 headers
No CORS headers found

Cookies Headers

0 headers
No cookies headers found

Other Headers

2 headers
Content-Security-Policy-Report-Only
Other
default-src 'self' data: blob: *.verisign.com *.brightcove.net *.cookielaw.org; report-uri /report-csp; img-src 'self' data: *.verisign.com *.siteimproveanalytics.io *.brightcove.com *.prod.boltdns.net *.vrsn.com *.cookielaw.org *.sc.omtrdc.net/; object-src 'none'; script-src 'strict-dynamic' 'sha256-Qlywh04o9RqzY3pRMVETyTW7Jfbg5Tzu4fKM5DsfERo=' 'sha256-kLnArxja6Bs6U2Il+xfeJn8veuH81wPxrw/ixeqvDT8=' 'sha256-Sh79HpVcRWbbh8F4vWgVVkmc5kGu923LZAOeMWUh2w0=' 'sha256-Sh79HpVcRWbbh8F4vWgVVkmc5kGu923LZAOeMWUh2w0=' 'sha256-r0mwgRVPIhWexF7020SoSyg7nS4sUr41+jF0gvQaJV4=' 'sha256-DzahDayNFEoUz+wus3ioBIpoQDQ08i/zH3pCScqWICY=' 'sha256-+qB++cp4k+Izi7u8vVq0ycjxNzwKmKmud31l0gCfwPk=' 'sha256-XfhXbgLiZndw4wQttCtlwRntxTnAXXHXH5oZdlTiCkc=' 'sha256-PkiHtGuW8aOw2cCDmzzFj6UZ7sXa/KVHkqmlnHZ4x4A=' 'sha256-zsUdUv3zZgq+oAoAr1wKRKaiIULmCH5HfWBehLiSGXg=' 'sha256-NHOoud63+2cBtSNi2IKnSBavAjzFYLOcGvkm/uiAZA4=' 'sha256-9cxvFRJs+pkTqyLJYARzDPz1UmNhF2zMtugmVy8FPHM=' 'sha256-jT8Zq0ZDASJUAGJcI2JQBqJ9tWt5LMfWyw62YIbqOJE=' 'sha256-ZZk/LrH7rKIyCirJiYDdNHSADxzxwez30zDWZ+xtJiE=' 'sha256-truTrv3vESVm1meLN38xeX1+9WwEUJgQ6Y4WEpx2sMA=' 'sha256-SRRUCF20jnbOSMxPsDmSPq4nvKhvMa2yvjk0XJfIsDo=' 'sha256-VZdU5UzIt6Y9Biwo8+VOYB5+zBCWuEEY0wFOdI6dPqY=' 'sha256-n5RLJSHxfgokM7LXckRgxbRdL9WQpr5INJ770xnv+u8=' 'sha256-ImKGMATRLQ7VVvCElMY+VI+Bc5Sztk1fFB3eDa8zUd8=' 'sha256-S4i1aR10IfngJLP8iRh9zAWtz3Lyg7IL4wZ1aVb/mcI=' 'sha256-vaIc3Fp4V1Ci4UD6/K3GbaZnei/1jWDKrOQwR23Czb8=' *.onetrust.com assets.adobedtm.com siteimproveanalytics.com players.brightcove.net *.zencdn.net *.salesforceliveagent.com *.verisign.com; style-src 'self' 'unsafe-inline'; connect-src 'self' *.prod.boltdns.net *.brightcove.com *.akamaihd.net *.greenhouse.io *.verisign.com *.vrsn.com *.cookielaw.org *.onetrust.com *.cludo.com *.sc.omtrdc.net dpm.demdex.net; worker-src blob:
Date
Other
Fri, 07 Nov 2025 08:43:21 GMT

Recommendations

Enable compression (gzip/brotli) to improve performance

Analysis completed in 101ms