Open
Cached
·
just now
19
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Good
max-age=63072000; includeSubDomains
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Missing
Not configured
Recommendations
- • Consider adding 'preload' to HSTS for maximum security
- • Add Content-Security-Policy header to prevent XSS attacks
- • Consider adding Permissions-Policy to control browser features
Performance Headers
2 headers
Connection
Performance
close
Transfer-Encoding
Performance
chunked
Caching Headers
2 headers
Cache-Control
Caching
max-age=0, private, must-revalidate
Etag
Caching
W/"af538f17d34b8306810688a7e2084d6b"
Content Headers
1 headers
Content-Type
Content
text/html; charset=utf-8
Server Headers
3 headers
Server
Server
nginx/1.26.2 + Phusion Passenger(R) 6.0.24
X-Powered-By
Server
Phusion Passenger(R) 6.0.24
X-Runtime
Server
0.035732
CORS Headers
0 headers
No CORS headers found
Cookies Headers
1 headers
Set-Cookie
Cookies
_agora_session=vlAoUwW6OPorXkOwNaKkWmC%2FoXc4hbGJT7jgTshCH3cimVbgCwYxLPitL1%2F004AnZLNCE%2BX6xpcsNkCTG0Tx4vMg2ZDckaNWixeS7G30B3SWnnEiWhElF8WauIeBvRUsUGrOuNLc7HdeD1arlUejZ4gv5V9J4yZt0gMHe2PcZVxt30Rb%2B4F80kh%2FnkOVrttaZpbe1%2B2MoqAos84tTUVHNj5HWRPfI82m0V%2BXY1q1NciXfnjQ5wgbbLALJXd02o2sRuStvfavfB7DOCWZg8HETUhHZU1H3A%3D%3D--KNsdvCtsXSyEoHj1--orxr92AIC%2Bm6K6Q9Uq2acA%3D%3D; path=/; secure; httponly; samesite=lax
Other Headers
5 headers
Date
Other
Sat, 27 Dec 2025 05:38:17 GMT
Link
Other
</assets/application-60d2cbb8e7a80d81d3aa59a536c1ebc5865a69be54e91c740dc9715fa5073bf2.css>; rel=preload; as=style; nopush,</assets/application-681f26782c52b30aa6817fe5d75f0837b1404ab8ef8ed068d1754c686a70da61.js>; rel=preload; as=script; nopush,</packs/css/application-4707e12a.css>; rel=preload; as=style; nopush,</packs/js/application-ae12c38dc4f83e97c351.js>; rel=preload; as=script; nopush
Status
Other
200 OK
X-Permitted-Cross-Domain-Policies
Other
none
X-Request-Id
Other
40b6ba41-048b-4bd7-b960-f3aa34d57cda
Recommendations
Enable compression (gzip/brotli) to improve performance
Consider removing X-Powered-By header to hide server technology
Analysis completed in 253ms