Technical Information
| HTTP Status Code | 200 |
| HTTP Version | HTTP/1.1 |
| HTTPS | ✔ Available |
| IP Address | 128.95.160.154 |
| Server Software | nginx/1.25.5 |
|
🔒 🟡 Mixed Content (8 HTTP resources) | The page is served over HTTPS but loads 8 resource(s) over HTTP. This may be blocked in modern browsers. |
|
🕐 🟡 Slow Response (1255 ms) | Response time exceeds 1 second. Consider optimizing the server or using caching. |
|
ℹ 🔵 Missing HSTS | HTTP Strict Transport Security is not configured. Recommended for HTTPS sites. |
|
ℹ 🔵 Missing Content Security Policy | CSP is not configured. It helps prevent XSS attacks and content injection. |
|
ℹ 🔵 No Compression | The server does not use Gzip or Brotli. Enable compression to reduce bandwidth usage. |
HTTP Status Code 200
HTTP Version HTTP/1.1
HTTPS ✔ Available
IP Address 128.95.160.154
Server Software nginx/1.25.5
🔒 🟡 Mixed Content (8 HTTP resources) The page is served over HTTPS but loads 8 resource(s) over HTTP. This may be blocked in modern browsers.
🕐 🟡 Slow Response (1255 ms) Response time exceeds 1 second. Consider optimizing the server or using caching.
ℹ 🔵 Missing HSTS HTTP Strict Transport Security is not configured. Recommended for HTTPS sites.
ℹ 🔵 Missing Content Security Policy CSP is not configured. It helps prevent XSS attacks and content injection.
ℹ 🔵 No Compression The server does not use Gzip or Brotli. Enable compression to reduce bandwidth usage.
Performance
| DNS Lookup | 452 ms |
| TCP Connect | 595.4 ms |
| TLS Handshake | 149.6 ms |
| Time To First Byte (TTFB) | 1255.3 ms |
| Content Download | 0.1 ms |
| Total Response Time | 1255.4 ms |
DNS Lookup 452 ms
TCP Connect 595.4 ms
TLS Handshake 149.6 ms
Time To First Byte (TTFB) 1255.3 ms
Content Download 0.1 ms
Total Response Time 1255.4 ms
Security
| HTTPS | ✔ Enabled |
| HSTS | ✘ Not configured |
| CSP | ⚠ Not configured |
| X-Frame-Options | ✔ SAMEORIGIN |
| X-Content-Type-Options | ✔ nosniff |
| Referrer Policy | strict-origin-when-cross-origin |
| HTTP/2 | ⚠ HTTP/1.1 |
HTTPS ✔ Enabled
HSTS ✘ Not configured
CSP ⚠ Not configured
X-Frame-Options ✔ SAMEORIGIN
X-Content-Type-Options ✔ nosniff
Referrer Policy strict-origin-when-cross-origin
HTTP/2 ⚠ HTTP/1.1
SEO Quick Check
Title Foldit
Detected Technologies
| Technology | Google Analytics Nginx PHP Matomo |
Technology Google Analytics Nginx PHP Matomo
HTTP Headers
| Server
| nginx/1.25.5 |
| Date
| Wed, 19 Aug 2026 22:42:55 GMT |
| Content-Type
| text/html; charset=utf-8 |
| Transfer-Encoding
| chunked |
| Connection
| keep-alive |
| X-Frame-Options
| SAMEORIGIN |
| X-XSS-Protection
| 1; mode=block |
| X-Content-Type-Options
| nosniff |
| X-Download-Options
| noopen |
| X-Permitted-Cross-Domain-Policies
| none |
| Referrer-Policy
| strict-origin-when-cross-origin |
| ETag
| W/"edee9912a587ee5cfd71e393db756c98" |
| Cache-Control
| max-age=0, private, must-revalidate |
| X-Request-Id
| 03534122-84f1-49dd-84ec-9266d6e3efe1 |
| X-Runtime
| 0.223915 |
Meta Tags
| Csrf-param | authenticity_token |
| Csrf-token | ls+Y8fNk4L7zAdK2WoPn5f0NeZ9+x6ttuNGBi8bKdI1XvvoQJUiWgcat3wGRAGkVvvGpEp3FvTHY1bQ3pz93KA== |
| Viewport | width=device-width, initial-scale=1 |
Server nginx/1.25.5
Date Wed, 19 Aug 2026 22:42:55 GMT
Content-Type text/html; charset=utf-8
Transfer-Encoding chunked
Connection keep-alive
X-Frame-Options SAMEORIGIN
X-XSS-Protection 1; mode=block
X-Content-Type-Options nosniff
X-Download-Options noopen
X-Permitted-Cross-Domain-Policies none
Referrer-Policy strict-origin-when-cross-origin
ETag W/"edee9912a587ee5cfd71e393db756c98"
Cache-Control max-age=0, private, must-revalidate
X-Request-Id 03534122-84f1-49dd-84ec-9266d6e3efe1
X-Runtime 0.223915