24 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31536000
Content-Security-Policy
Weak
require-trusted-types-for
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Present
ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factors=*, ch-ua-platform=*, ch-ua-platform-version=*
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Significantly strengthen CSP directives
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)

Performance Headers

3 headers
Accept-Ranges
Performance
none
Transfer-Encoding
Performance
chunked
Vary
Performance
Sec-CH-Viewport-Width, Sec-CH-DPR,Accept-Encoding

Caching Headers

3 headers
Cache-Control
Caching
no-cache, no-store, max-age=0, must-revalidate
Expires
Caching
Mon, 01 Jan 1990 00:00:00 GMT
Pragma
Caching
no-cache

Content Headers

1 headers
Content-Type
Content
text/html; charset=utf-8

Server Headers

1 headers
Server
Server
ESF

CORS Headers

0 headers
No CORS headers found

Cookies Headers

1 headers
Set-Cookie
Cookies
VISITOR_PRIVACY_METADATA=CgJVUxIEGgAgUg%3D%3D; Domain=.youtube.com; Expires=Sun, 17-May-2026 06:12:30 GMT; Path=/; Secure; HttpOnly; SameSite=none

Other Headers

8 headers
Accept-Ch
Other
Sec-CH-Viewport-Width, Sec-CH-DPR
Alt-Svc
Other
h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
Date
Other
Tue, 18 Nov 2025 06:12:30 GMT
Document-Policy
Other
include-js-call-stacks-in-crash-reports
Origin-Trial
Other
AiDEBptUfVeO93q48VdVMe/ubupazdAl8AaHP+NBzdnW8quUcHdzJUyGSfrmtpKJu7EOvwRp9ug2rEo3XU+WMAMAAAB2eyJvcmlnaW4iOiJodHRwczovL3lvdXR1YmUuY29tOjQ0MyIsImZlYXR1cmUiOiJEZXZpY2VCb3VuZFNlc3Npb25DcmVkZW50aWFsczIiLCJleHBpcnkiOjE3NzQzMTA0MDAsImlzU3ViZG9tYWluIjp0cnVlfQ==
P3p
Other
CP="This is not a P3P policy! See http://support.google.com/accounts/answer/151657?hl=en for more info."
Report-To
Other
{"group":"youtube_main","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/youtube_main"}]}
Reporting-Endpoints
Other
default="/web-reports?context=eJwN0H9I1Hccx3G-Plfp3Xnf-37fnzB0rDDNhjvzHA6cFG0xk_LKoF_zGtqPu5CZpt1dJxgkLLZRbqwfVtovozK0XxQFak7GoKzIII2sdIX9EbLoxyCrzc19_njA-w0vXrx5OwYnzRr41ghNbDLSCiuNC9uqjTUZNcZXd7YYuwrCRn1R2Bg7FTbOdoWN5zOiRiA1ahy4FzUqHseMI57VcbHk1XFdJQ5CIQdvDjp4PeQg9tJBINNJ_yInz5c4udLqpOuik-FnTiIBF6_KXORGXFSNuRgtTqT7YCJrRxL5ZLmb0x1uiq-7-UV78a-bDJ9JXZ7JZ3NNokETZ9Sk6UcT336T-BaTpJsm3Wke8vwe4ss8OLS7zXo-72HorYf8vz18IxaHVlgMl1r4N1rU1Vl8py3eYfHlTxbzGi162ixSzlnIgMWHoxYj7yzcCTaFc2weFthMLLLxB2yk0eb3Hpu5fTb5d23S79skjdnETxEGnEL2VGFJsuBPEdqnC5IqLEgTCtOF1izBmyv05AkP8oXgfKF6gRBZKrzTmkt0NiDMDAqOKmGP9ke1sKNG-OJ7IfSDENgnXG4SDrcIPx8XFp4UfmsX4s4IN7ToRaH7kvCkQyjrFN5f0_29OnNLWHZbGOkTCgaFWm3aI32XNvFYODoiuJ4Kbq3hmZD-p7D3L519r-_VRrXxf4SscWHlBwpcii3af4mKercibCmKkxSNHykmz1QUZSi2ZypCixWGX-_azmJF0yrFce3zrxVHShTNQUV7ueKsdkEbjyjmxxRXaxWddbpf-3i7YlO90j9QJOxSVGo9DYpP9ypiLYrZJxS7tX5ta6siuU0xq11hu-L7Dr3qnew59uuVtrhUb21VJBxZF8zaGlznDdVUVYa9wcoN3vU15eHy9WsrSnOyc3J9Pl9Oli-7dHP2__2-3MY"

Recommendations

Enable compression (gzip/brotli) to improve performance

Analysis completed in 518ms