CSP is not configured. It helps prevent XSS attacks and content injection.
ℹ 🔵Missing X-Frame-Options
The site can be embedded in iframes by third parties (clickjacking risk).
ℹ 🔵No Compression
The server does not use Gzip or Brotli. Enable compression to reduce bandwidth usage.
HTTP Status Code200 HTTP VersionHTTP/1.1 HTTPS✔ Available IP Address34.149.250.58 ℹ 🔵Missing Content Security PolicyCSP is not configured. It helps prevent XSS attacks and content injection. ℹ 🔵Missing X-Frame-OptionsThe site can be embedded in iframes by third parties (clickjacking risk). ℹ 🔵No CompressionThe server does not use Gzip or Brotli. Enable compression to reduce bandwidth usage.
Performance
DNS Lookup
52 ms
TCP Connect
54.4 ms
TLS Handshake
12.4 ms
Time To First Byte (TTFB)
79.4 ms
Content Download
0 ms
Total Response Time
79.5 ms
DNS Lookup52 ms TCP Connect54.4 ms TLS Handshake12.4 ms Time To First Byte (TTFB)79.4 ms Content Download0 ms Total Response Time79.5 ms
Security
HTTPS
✔ Enabled
HSTS
✔ max-age=63072000; includeSubDomains; preload
CSP
⚠ Not configured
X-Frame-Options
⚠ Not configured
X-Content-Type-Options
⚠ Not configured
HTTP/2
⚠ HTTP/1.1
HTTPS✔ Enabled HSTS✔ max-age=63072000; includeSubDomains; preload CSP⚠ Not configured X-Frame-Options⚠ Not configured X-Content-Type-Options⚠ Not configured HTTP/2⚠ HTTP/1.1
HTTP Headers
Date
Wed, 19 Aug 2026 22:01:49 GMT
Content-type
application/json; charset=utf-8
Strict-transport-security
max-age=63072000; includeSubDomains; preload
Content-length
19
Vary
origin
X-varnish-age
0
Accept-ranges
bytes
Via
1.1 google
Alt-svc
h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
DateWed, 19 Aug 2026 22:01:49 GMT Content-typeapplication/json; charset=utf-8 Strict-transport-securitymax-age=63072000; includeSubDomains; preload Content-length19 Varyorigin X-varnish-age0 Accept-rangesbytes Via1.1 google Alt-svch3=":443"; ma=2592000,h3-29=":443"; ma=2592000