Cached · just now
22 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains
Content-Security-Policy
Weak
upgrade-insecure-requests
X-Frame-Options
Present
ALLOW-FROM https://builder.io
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Missing
Not configured
Recommendations
  • Consider adding 'preload' to HSTS for maximum security
  • Significantly strengthen CSP directives
  • Consider adding Permissions-Policy to control browser features

Performance Headers

2 headers
Connection
Performance
Transfer-Encoding
Transfer-Encoding
Performance
chunked

Caching Headers

2 headers
Cache-Control
Caching
max-age=72467
Expires
Caching
Sat, 24 Jan 2026 16:29:02 GMT

Content Headers

1 headers
Content-Type
Content
text/html

Server Headers

1 headers
Server
Server
Apache

CORS Headers

2 headers
Access-Control-Allow-Headers
Cors
X-Requested-With
Access-Control-Allow-Origin
Cors
www.schneider-electric.cn

Cookies Headers

1 headers
Set-Cookie
Cookies
bm_sz=23447C71B35C5AE036FC12CA49348F36~YAAQmWvcF84WK8ibAQAACKeE7B7tLl9nWJz+KXyA0QZNfyMvA+803pyl/AJEzAj+TKwWZX1NkVTWbjsd+WBCfwas9qgo5wGdh9Wxi7lnHpKs69ztEOSRJVnt+UL9mnaBULhrq+qU6T7scJLQ4syAN0OfRfQOoxFa8TMZB3aXbBL9yXccflFaon8MhPc2fuS8oN3Tho45LACn9nSEAW6SJ2M3d7Z0IASCAQz4bRzD+PsbgRXEPUSqhjkjzIbWPNpTcfSrabypzg8rTAbKyW4CTW0ITC3AeL8sx5c1id4tlkq6PZWO17iqJgasWU9VhmWGuwDWii9Q9Y8SuUYwvrA6Dhh+A4r4Pbd/gb/Y80J6v4SVI7tXMqcuPQ==~4408881~3490866; Domain=.schneider-electric.cn; Path=/; Expires=Sat, 24 Jan 2026 00:21:15 GMT; Max-Age=14400

Other Headers

7 headers
Content-Security-Policy-Report-Only
Other
default-src 'self' blob: https: data: mediastream: 'unsafe-eval' 'unsafe-inline'; connect-src cdn.builder.codes *.builder.io *.schneider-electric.com *.se.com glue.pes-stg.cloud.spryker.toys service.force.com *.apc.com nebula-cdn.kampyle.com ubt-eu.kampyle.com sbt-prod.kampyle.com udc-neb.kampyle.com *.ariba.com *.amazonaws.com twitter.com zinfi.net firebaselogging-pa.googleapis.com firebaseremoteconfig.googleapis.com firebaseinstallations.googleapis.com resources.digital-cloud.medallia.eu/ partnerassessment.secure.force.com se.my.salesforce.com se.my.salesforce-sites.com *.salesforceliveagent.com *.squared.com/* *.onetrust.com seadvantage.force.com:443/ seadvantage.my.site.com:443/ seadvantage.my.site.com/* *.pendo.io tag.commander1.com www.google-analytics.com *.google.com salesforce.com salesforceliveagent.com documentforce.com kampyle.com force.com cookielaw.org unpkg.com cdn.jsdelivr.net *.demandbase.com twimg.com *.twimg.com *.youtube.com *.zinfi.net *.google.ru akstat.io *.go-mpulse.net/* microsoft.com *.clipsal.com/* cdn.cookielaw.org maxcdn.bootstrapcdn.com *.dynatrace.com *.kampyle.com *.google-analytics.com *.amazoncognito.com *.doubleclick.net googlemaps.github.io *.googlemaps.github.io/* maps.googleapis.com *.googleapis.com *.zscaler.net static.lightning.force.com www.apc.com api.company-target.com js-cdn.dynatrace.com c.go-mpulse.net *.akstat.io *.applanga.com 'self' *.akstat.io/ *.d2osz8slymlqdp.cloudfront.net *.google.com.sa *.google.by su.symexbelgium.com d2osz8slymlqdp.cloudfront.net d2cbq57joo8non.cloudfront.net use.typekit.net wss://*.execute-api.us-east-1.amazonaws.com wss://*.iot.us-east-1.amazonaws.com wss://4g5de7bcl4.execute-api.us-east-1.amazonaws.com wss://545sekhka2.execute-api.us-east-1.amazonaws.com wss://a307bjgfbycsj5-ats.iot.us-east-1.amazonaws.com wss://fjwji5pjgbbzzp2xmyispmyo6u.appsync-realtime-api.us-east-1.amazonaws.com wss://ixbskdr5a5bnbhl3qtwi5nhslu.appsync-realtime-api.us-east-1.amazonaws.com wss://qjye63smz5ggbb33xs4rn6hoiq.appsync-realtime-api.us-east-1.amazonaws.com wss://tu43ymv7pc.execute-api.us-east-1.amazonaws.com wss://0jyqaecg5j.execute-api.us-east-1.amazonaws.com wss://a307bjgfbycsj5-ats.iot.us-east-1.amazonaws.com wss://xbezullc75gyffaqf3npo2pavi.appsync-realtime-api.us-east-1.amazonaws.com; report-uri https://semyschneiderweb.report-uri.com/r/t/csp/reportOnly; script-src 'self' blob: https: data: mediastream: 'unsafe-eval' 'unsafe-inline' 'nonce-QmMfx0nVEkKN5q8oXN1fwg=='
Date
Other
Fri, 23 Jan 2026 20:21:15 GMT
X-Akamai-Transformed
Other
0 - 0 -
X-Amz-Cf-Id
Other
60a9VZSj9MBJE2y3P0uaZFcYrTli71DYy4jnYFtVu-aFVmtym2EwLw==
X-Amz-Cf-Pop
Other
IAD61-P3
X-Sveltekit-Page
Other
true
X-Ua-Compatible
Other
IE=edge,chrome=1

Recommendations

Enable compression (gzip/brotli) to improve performance