Technical Information
| HTTP Status Code | 200 |
| HTTP Version | HTTP/1.1 |
| HTTPS | ✔ Available |
| IP Address | 104.18.12.69 |
| Server Software | cloudflare |
| CDN | Cloudflare |
| Compression | gzip |
|
ℹ 🔵 Missing X-Frame-Options | The site can be embedded in iframes by third parties (clickjacking risk). |
HTTP Status Code 200
HTTP Version HTTP/1.1
HTTPS ✔ Available
IP Address 104.18.12.69
Server Software cloudflare
CDN Cloudflare
Compression gzip
ℹ 🔵 Missing X-Frame-Options The site can be embedded in iframes by third parties (clickjacking risk).
Redirect Chain
| # | URL | HTTP Status Code | Status |
| 1 | https://barillet.fr:443 | 301 | HTTP/2 301 |
| 2 | https://www.barillet-distribution.fr/ | 200 | HTTP/2 200 |
#1 URL https://barillet.fr:443
HTTP Status Code 301
Status HTTP/2 301
#2 URL https://www.barillet-distribution.fr/
HTTP Status Code 200
Status HTTP/2 200
Performance
| DNS Lookup | 18.3 ms |
| TCP Connect | 20.1 ms |
| TLS Handshake | 8.3 ms |
| Time To First Byte (TTFB) | 70.1 ms |
| Content Download | 0.1 ms |
| Total Response Time | 70.2 ms |
DNS Lookup 18.3 ms
TCP Connect 20.1 ms
TLS Handshake 8.3 ms
Time To First Byte (TTFB) 70.1 ms
Content Download 0.1 ms
Total Response Time 70.2 ms
Security
| HTTPS | ✔ Enabled |
| HSTS | ✔ max-age=15552000; includeSubDomains; preload |
| CSP | ✔ Configured |
| X-Frame-Options | ⚠ Not configured |
| X-Content-Type-Options | ✔ nosniff |
| Referrer Policy | strict-origin-when-cross-origin |
| HTTP/2 | ⚠ HTTP/1.1 |
HTTPS ✔ Enabled
HSTS ✔ max-age=15552000; includeSubDomains; preload
CSP ✔ Configured
X-Frame-Options ⚠ Not configured
X-Content-Type-Options ✔ nosniff
Referrer Policy strict-origin-when-cross-origin
HTTP/2 ⚠ HTTP/1.1
Detected Technologies
| Technology | Google Analytics Cloudflare |
Technology Google Analytics Cloudflare
HTTP Headers
| Date
| Thu, 20 Aug 2026 05:56:50 GMT |
| Content-type
| text/html |
| Cache-control
| no-cache |
| Content-security-policy
| connect-src https: 'self'; img-src 'self' data: https://*; default-src blob: https: 'unsafe-inline' 'unsafe-eval' |
| Expires
| Thu, 01 Jan 1970 00:00:01 GMT |
| Referrer-policy
| strict-origin-when-cross-origin |
| Strict-transport-security
| max-age=15552000; includeSubDomains; preload |
| X-content-type-options
| nosniff |
| X-xss-protection
| 1; mode=block |
| Cf-cache-status
| DYNAMIC |
| Content-encoding
| gzip |
| Server
| cloudflare |
| Cf-ray
| a2df2834ae5c4fe6-CDG |
Date Thu, 20 Aug 2026 05:56:50 GMT
Content-type text/html
Cache-control no-cache
Content-security-policy connect-src https: 'self'; img-src 'self' data: https://*; default-src blob: https: 'unsafe-inline' 'unsafe-eval'
Expires Thu, 01 Jan 1970 00:00:01 GMT
Referrer-policy strict-origin-when-cross-origin
Strict-transport-security max-age=15552000; includeSubDomains; preload
X-content-type-options nosniff
X-xss-protection 1; mode=block
Cf-cache-status DYNAMIC
Content-encoding gzip
Server cloudflare
Cf-ray a2df2834ae5c4fe6-CDG