9 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

Performance Headers

2 headers
Connection
Performance
keep-alive
Transfer-Encoding
Performance
chunked

Caching Headers

0 headers
No caching headers found

Content Headers

1 headers
Content-Type
Content
text/html; charset=UTF-8

Server Headers

1 headers
Server
Server
nginx/1.18.0 (Ubuntu)

CORS Headers

3 headers
Access-Control-Allow-Headers
Cors
X-Requested-With
Access-Control-Allow-Methods
Cors
POST, GET, DELETE, PUT, PATCH, OPTIONS
Access-Control-Allow-Origin
Cors
*

Cookies Headers

1 headers
Set-Cookie
Cookies
sessao_infinit=a%3A5%3A%7Bs%3A10%3A%22session_id%22%3Bs%3A32%3A%22395cc1596738c7e86a9e00379cc87ffa%22%3Bs%3A10%3A%22ip_address%22%3Bs%3A12%3A%2264.34.81.165%22%3Bs%3A10%3A%22user_agent%22%3Bs%3A10%3A%22mint%2F1.7.1%22%3Bs%3A13%3A%22last_activity%22%3Bi%3A1762911579%3Bs%3A9%3A%22user_data%22%3Bs%3A0%3A%22%22%3B%7Da29b40620c3f1320fd424481d23f452c; expires=Wed, 12 Nov 2025 03:39:39 GMT; Max-Age=7200; path=/

Other Headers

1 headers
Date
Other
Wed, 12 Nov 2025 01:39:39 GMT

Recommendations

Enable compression (gzip/brotli) to improve performance

Add Cache-Control header to optimize caching

Analysis completed in 0ms