24 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31536000
Content-Security-Policy
Basic
script-src; object-src; base-uri; +2 more
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Present
ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factors=*, ch-ua-platform=*, ch-ua-platform-version=*
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Improve CSP by adding more specific directives and removing 'unsafe-inline'
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)

Performance Headers

3 headers
Accept-Ranges
Performance
none
Transfer-Encoding
Performance
chunked
Vary
Performance
Sec-Fetch-Dest, Sec-Fetch-Mode, Sec-Fetch-Site,Accept-Encoding

Caching Headers

3 headers
Cache-Control
Caching
no-cache, no-store, max-age=0, must-revalidate
Expires
Caching
Mon, 01 Jan 1990 00:00:00 GMT
Pragma
Caching
no-cache

Content Headers

1 headers
Content-Type
Content
text/html; charset=utf-8

Server Headers

1 headers
Server
Server
ESF

CORS Headers

0 headers
No CORS headers found

Cookies Headers

1 headers
Set-Cookie
Cookies
CONSISTENCY=AKctkzlbNkxBVE_vXWTJZYr3mSzreyL3HG0RLQOjV6krUyomxH39rMZNExARcESdPJDKxwU8CmXEh8QgfcU8T0UXl_ByXMi5gUt2sgOQYzrQW11QekORbcJqsse6gWoYwdOMujG6EmkQ; Domain=.google.com; Expires=Sat, 08-Nov-2025 14:24:32 GMT; Path=/; Secure; HttpOnly

Other Headers

7 headers
Accept-Ch
Other
Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factors, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
Alt-Svc
Other
h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
Content-Security-Policy-Report-Only
Other
require-trusted-types-for 'script';report-uri /_/Gstore/cspreport
Date
Other
Sat, 08 Nov 2025 14:19:32 GMT
P3p
Other
CP="This is not a P3P policy! See g.co/p3phelp for more info."
Reporting-Endpoints
Other
default="/_/Gstore/web-reports?context=eJwVyHtUk3Ucx_H5te8P07I0M-SSl9K8hqBokUVeUmMXL5AVpISGKZ5AQVIxwzjK1KQrMsCsjpJBdXQVKUxRsUBN5dkGgz3PBuSeDTYSTFFLPWaf_nid8_58-pcNHN8_RKMfG6JpTwnVdIDmSrxmcJqpT1F9Ff09t5qm6Kvp2e3V9OZwC1WOslBCgoVK0i3Ub72FsvIstOyQhYbWWSgYpp-30O3LFtq64Bjlwd7Nxyj322OkxMg0PEmm6FUyrYGaLJmqCmR6olCmA6Uy1cMZKK-V6fRZmYw2mdLsMnW3yVTYLdMAUmhblEJjZyo0HkqTFfoCLq5X6IdshTacVuhqr0JR_V00FbaFuKhllYtCy1x0qcJFX6suOt_jor193NR2n5uKgty0dpibTk5xU3ORhw5Xeqje4qEI2UOy10P5dz2UOEyl6oUqDU9QaekrKh1artKnK1XSfKDS5O0qXT-qkr1OpdSzKr3brtIGqOxUadEVleiOSoPuqdRGXkplL7UHealqiJeME700dZKXSiK9VLbQS9bVXjqT5aWG79BmL41p91IkVE7wkWOKjz6c7qPDL_voxY0-Mu3x0fYSH-VYfLTO6qNFbh8Ze3y0AzKCOsj3dgflZ3fQheYO2qd00DR_B8kzO-nWq51UY-6knfZOSvirkyYM9dM3YX46ONJPtgI_3fzITzN6_PT5yACVQP3UAF2A5wwBioVXEwO0FD5_I0C_gnZVgBbBMngLZuYHKLEyQMOOB-hmcBfdgxnDumgF_DnPxL1QMd_EE182sXGBiQug0GziUoisNvH0_50w8fOw1WPifBh_w8RRcGJIMddD_FPFnAR1h4v5IvRWFfN2uYH3wC-9DVwD7XcbuBPKNRKb4XIfia-Db5DE3TAmWOKnISZM4tlgXSGxExTwgLRJ4hb46X2JLbA7V-I9kLJD4tWQWyKxEXbtl7gUug5IfA02XZB4nUPiYJ_EI2Bir8RTYUZfK8-B2WFW1kL5BCuboS7FyhchaYOVV4DnQyt3QfNuK7dB3mErb4PBXVYOhfvvWHkQlIfb2AzvjLJxNpgX27gK_PttfBUyf7FxDuT6bWyEoNs2fggiR9h5Jqx8yc7pEDzXziPgbLydwxPs_PASfNCUbGc3yEY7X4LwIjuPhnLZzmaQZzXyJcjNaGQjROQ18nTILm7kLfBYeSNvhEVKI78OmcFNnAe105r4HCxNaeJUqLVgg2hp4oGwW27iQlDGOdgD5XoHm0Gz2sH9YPYaB2shM8fBObC4ysGJcKLXwfXQOraZfXCmvpklCLc282jwh7bwVbhvSQs_AN3rW7gX5hS0sA6-rGrhr-DxECePAV2Ek1_53zNOXgqnYpx8Dq7lOHnwZidn_-zkLbBGcXIWLA-SORMOhsp8CGoLZD4Ht6_L3PeGzPnPK2yEjjKFeyC6VuGXYMzHLo6ASKeLn4WUuy5Og9hH3TwPGird3AxHT7j5JNi2trIMj-5q5XCYW9nKBog908rzIf2fVn4XKvq38SX_PQ5A4v1xYjmEDI0To2CSI05Ew7jeOBEFMTAL2gdqRScs02vFSghaqBUPQXmaVpjhtTVakQLH4TdI2qIVKyD1E61Ih7RCrciCq_u04hakfq8V78CmJq34AIaM0IkwGDdSJ6Kg8D2d2Ad7d-pEGfx7RCfEUZ3QnNKJflD3m05chCa7TrjhUIReHIG1MXqxEeam64UBpu3Ui1gI_UwvnoAXf9CL-ZAX0ItdwN168SC4njQIFabNMYgXwLvTIC7Dkr0GkQwDfjSIR0AL8RBbaRDzoOKIQfwIXa094goMfqDf9f01Z8XDf_z-5yc0Knx5xrrkt7PWZ2SmTkpPzUiOmhwVHRk5OfrpyVHJayP_A1GnLms"
X-Ua-Compatible
Other
IE=edge

Recommendations

Enable compression (gzip/brotli) to improve performance

Analysis completed in 794ms