Open
Cached
·
just now
16
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Excellent
max-age=31536000; includeSubDomains; preload
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Significantly strengthen CSP directives
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
connection: close
Caching Headers
Etag
"1f2-4cb1d3b2ae680-gzip"
Last-Modified
Wed, 03 Oct 2012 01:05:14 GMT
etag: "1f2-4cb1d3b2ae680-gzip" last-modified: Wed, 03 Oct 2012 01:05:14 GMT
Content Headers
Content-Length
498
Content-Type
text/html
content-length: 498 content-type: text/html
Server Headers
Server
Apple
server: Apple
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Date
Wed, 15 Apr 2026 00:20:19 GMT
Reporting-Endpoints
aos-csp-error="https://www.apple.com/shop/mdp/api/csp-error"
Server-Timing
app;dur=0.007786, dc;desc=ucp3
X-Nxid
e869377d7adcea89490a082fcfaf94a3
X-Shred
42b9deb1cf30d63bc6fa54f1a858174f
date: Wed, 15 Apr 2026 00:20:19 GMT reporting-endpoints: aos-csp-error="https://www.apple.com/shop/mdp/api/csp-error" server-timing: app;dur=0.007786, dc;desc=ucp3 x-nxid: e869377d7adcea89490a082fcfaf94a3 x-shred: 42b9deb1cf30d63bc6fa54f1a858174f
Recommendations
Enable compression (gzip/brotli) to improve performance
Add Cache-Control header to optimize caching