19 Headers

Detected Technologies from Headers

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=3153600; includeSubDomains; preload;, max-age=31536000; includeSubDomains
Content-Security-Policy
Basic
default-src; img-src; script-src; +6 more Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Present
SAMEORIGIN, SAMEORIGIN
X-Content-Type-Options
Present
nosniff, nosniff
Referrer-Policy
Present
strict-origin-when-cross-origin, no-referrer-when-downgrade
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Improve CSP by adding more specific directives and removing 'unsafe-inline'
  • Consider adding Permissions-Policy to control browser features

Performance Headers

Connection
Performance
close
Content-Encoding
Performance
binary

Caching Headers

Cache-Control
Caching
max-age=0, must-revalidate
Etag
Caching
"df-77293c77cc8fe1a53f1922d5dc2e484c"

Content Headers

Content-Encoding
Content
binary
Content-Length
Content
67490
Content-Type
Content
text/html; charset=UTF-8

Server Headers

Server
Server
Sucuri/Cloudproxy

CORS Headers

No CORS headers found

Cookies Headers

Set-Cookie
Cookies

Other Headers

Alt-Svc
Other
h3=":443"; ma=2592000, h3-29=":443"; ma=2592000
Date
Other
Sun, 03 May 2026 02:21:55 GMT
X-Sucuri-Cache
Other
MISS
X-Sucuri-Id
Other
14018
X-Ua-Compatible
Other
IE=Edge,chrome=IE8

Recommendations

No recommendations at this time