arrivabus.co.uk | Analytics by SecurityHeaders

HTTP Headers report for arrivabus.co.uk

Header Name Header Data
HTTP status code 200
X-Amz-Cf-Pop AMS54-C1
X-Content-Type-Options nosniff
Connection keep-alive
Cf-Cache-Status DYNAMIC
Last-Modified Fri, 06 Sep 2024 02:55:28 GMT
Strict-Transport-Security max-age=15552000; includeSubDomains; preload
Referrer-Policy same-origin
Vary Accept-Encoding
Content-Security-Policy default-src 'self' google.com/forms/ *.ak.facebook.com *.arrivabus.co.uk *.betrad.com *.bing.com *.facebook.com *.google.com *.spotify.com *.tiqcdn.com *.twitter.com *.youtube.com akamaiedge.net api.braintreegateway.com api.instagram.com apps.spotify.edgekey.net arriva.acquiadam.com arrivabus.zendesk.com cloudfront.net crowdfunding.justgiving.com/justgiving.com/ d2c87l0yth4zbw.cloudfront.net ekr.zdassets.com facebook.co.uk facebook.com fbcdn.netfbsbx.com googlesyndication.com googlevideo.com instagram.com locpub.com mixcoud.com origin-analytics.braintree-api.com pinimg.com pinterest.com play.spotify.edgekey.net polldaddy.com rtb.locpub.com scontent-sjc3-1.cdninstagram.com s-media-cache-ak0.pinimg.com soundcloud.com spapps.cosp s-passets-cache-ak0.pinimg.com star.c10r.facebook.com static.zdassets.com t.co twimg.com twimg0-a.akamaihd.net twitter.com vimeo.com vimeocdn.com vupload2.t.facebook.com wss://*.zendesk.com wss://*.zopim.com www.google-analytics.com www.googletagmanager.com www.paypal.com google.com/pay pay.google.com/* www.slideshare.net www.youtube-nocookie.com youtube.com youtube.l.google.com ytimg.com ytimg.l.google.com *.onetrust.com 'unsafe-eval' 'unsafe-inline' ; script-src 'self' *.audiencemanager.de *.cardinalcommerce.com *.dynatrace.com *.facebook.net *.quantcount.com *.quantserve.com *.surveymonkey.com *.teads.tv ajax.googleapis.com analytics.tiktok.com apis.google.com assets.zendesk.com audiencemanager.de az416426.vo.msecnd.net clarity.microsoft.com ads.tiktok.com tiktok.com code.jquery.com leadforensics.com maps.googleapis.com my.tealiumiq.com optimize.google.com pay.google.com pfw-prod-ukwest-safespaceonline.azurewebsites.net s.yimg.com secure.adnxs.com sp.analytics.yahoo.com static.zdassets.com surveymonkey.com tags.tiqcdn.com translate.google.com translate.googleapis.com visitor-service-eu-central-1.tealiumiq.com widget-mediator.zopim.com www.clarity.ms www.googleadservices.com www.google-analytics.com www.googleanalytics.com www.googleoptimize.com www.googletagmanager.com www.microsoft.com www.paypal.com www.paypalobjects.com www.webinsights.com 'unsafe-eval' 'unsafe-inline' ; script-src-elem 'self' *.audiencemanager.de *.cardinalcommerce.com *.dynatrace.com *.facebook.net *.quantcount.com *.quantserve.com *.surveymonkey.com *.teads.tv ajax.googleapis.com api.exponea.arriva.co.uk apis.google.com assets.zendesk.com audiencemanager.de az416426.vo.msecnd.net bat.bing.com c.clarity.ms clarity.microsoft.com code.jquery.com connect.facebook.net googleads.g.doubleclick.net googleoptimize.com leadforensics.com maps.googleapis.com my.tealiumiq.com optimize.google.com pay.google.com pfw-prod-ukwest-safespaceonline.azurewebsites.net s.yimg.com secure.adnxs.com secure.leadforensics.com sp.analytics.yahoo.com static.zdassets.com surveymonkey.com tags.tiqcdn.com translate.google.com translate.googleapis.com visitor-service-eu-central-1.tealiumiq.com widget-mediator.zopim.com www.clarity.ms www.facebook.com www.google.ca www.google.co.uk www.google.com www.google.com.br www.google.com.hk www.google.com.my www.google.com.om analytics.tiktok.com ads.tiktok.com tiktok.com www.google.com.ua www.google.cz www.google.it www.google.lt www.google.nl www.google.pl www.googleadservices.com www.googleanalytics.com www.google-analytics.com www.googleoptimize.com www.googletagmanager.com www.microsoft.com www.paypal.com www.paypalobjects.com www.webinsights.com https://static.cloudflareinsights.com *.onetrust.com 'unsafe-inline' ; connect-src 'self' *.arrivabus.co.uk *.cardinalcommerce.com *.dynatrace.com *.teads.tv *.zendesk.com analytics.google.com analytics.tiktok.com api.braintreegateway.com api.exponea.arriva.co.uk apps.parcelforce.com bat.bing.com client-analytics.braintreegateway.com ads.tiktok.com tiktok.com collect.tealiumiq.com connect.facebook.net ekr.zdassets.com googleads.g.doubleclick.net googleoptimize.com maps.googleapis.com my.tealiumiq.com origin-analytics.braintree-api.com payments.braintree-api.com region1.analytics.google.com region1.google-analytics.com s.yimg.com secure.leadforensics.com stats.g.doubleclick.net translate.googleapis.com ukwest-0.in.applicationinsights.azure.com widget-mediator.zopim.com wss://widget-mediator.zopim.com www.clarity.ms www.facebook.com google.com/pay pay.google.com/* www.google.ca www.google.co.uk www.google.com www.google.com.br www.google.com.hk www.google.com.my www.google.com.om www.google.com.ua www.google.cz www.google.it www.google.lt www.google.nl www.google.pl www.google-analytics.com www.paypal.com *.onetrust.com 'unsafe-inline' ; img-src 'self' *.audiencemanager.de *.google.com *.quantcount.com *.quantserve.com *.surveymonkey.com *.teads.tv ajax.googleapis.com analytics.tiktok.com arrivabus.prod.acquia-sites.com audiencemanager.de bat.bing.com c.bing.com c.clarity.ms collect.tealiumiq.com connect.facebook.net content.api.arrivabus.co.uk googleads.g.doubleclick.net googleoptimize.com linkmaker.itunes.apple.com maps.googleapis.com maps.gstatic.com optimize.google.com pfw-prod-ukwest-safespaceonline.azurewebsites.net region1.analytics.google.com region1.google-analytics.com s.yimg.com secure.adnxs.com secure.leadforensics.com sp.analytics.yahoo.com rtb.locpub.com locpub.com t.paypal.com ads.tiktok.com tiktok.com translate.google.com translate.googleapis.com www.clarity.ms www.facebook.com www.google.ca www.google.co.in www.google.co.uk www.google.com www.google.com.br www.google.com.hk www.google.com.my www.google.com.om www.google.com.pk www.google.com.ua www.google.cz www.google.de www.google.ie www.google.it www.google.lt www.google.nl www.google.pl www.google-analytics.com www.googletagmanager.com google.com/pay pay.google.com/* www.gstatic.com *.onetrust.com blob: data: 'unsafe-inline' ; media-src *.audiencemanager.de *.surveymonkey.com ajax.googleapis.com audiencemanager.de secure.adnxs.com static.zdassets.com surveymonkey.com ; font-src 'self' *.fls.doubleclick.net *.google.com ajax.googleapis.com app-nc.global.ssl.fastly.net arrivabus.cloudflareaccess.com assets.braintreegateway.com assets.zendesk.com fonts.googleapis.com fonts.gstatic.com pfw-prod-ukwest-safespaceonline.azurewebsites.net secure.adnxs.com surveymonkey.com www.facebook.com ; frame-src 'self' accounts.google.com * *.audiencemanager.de *.cardinalcommerce.com *.surveymonkey.com 9458815.fls.doubleclick.net ajax.googleapis.com assets.braintreegateway.com bytedance: c.clarity.ms checkout.paypal.com connect.facebook.net googleoptimize.com optimize.google.com pay.google.com secure.adnxs.com secure.leadforensics.com sslocal: surveymonkey.com www.paypal.com www.youtube.com ; style-src *.arrivabus.co.uk *.audiencemanager.de *.surveymonkey.com ajax.googleapis.com assets.braintreegateway.com audiencemanager.de fonts.googleapis.com optimize.google.com pfw-prod-ukwest-safespaceonline.azurewebsites.net secure.adnxs.com surveymonkey.com translate.googleapis.com vimeo.com www.paypal.com www.youtube.com 'unsafe-inline' ; worker-src 'self' c.clarity.ms googleoptimize.com secure.leadforensics.com www.google.ca www.google.co.uk www.google.com www.google.com.br www.google.com.hk www.google.com.my www.google.com.om www.google.com.ua www.google.cz www.google.it www.google.lt www.google.nl www.google.pl blob: ; script-src-attr ajax.googleapis.com ;
X-Amz-Version-Id null
Server cloudflare
Date Tue, 13 May 2025 07:01:05 GMT
Cf-Ray 93f04856097761f9-AMS
Age 11974
X-Amz-Cf-Id kpPO7RFSFMkYQagO8_GT538B2AwZgAzxFz-LS73iWHvi7acetyswiA==
X-Cache Hit from cloudfront
Content-Type text/html
Via 1.1 1bc76a14967a660022b25f573baec632.cloudfront.net (CloudFront)
X-Frame-Options DENY
X-Xss-Protection 1; mode=block

About the tool

By using SecurityHeaders.info, you can quickly identify missing or misconfigured headers and take steps to secure your website, improving both security and user confidence.

This tool is widely used by developers, security professionals, and organizations to ensure their websites adhere to best practices in web security.

We also have another analytic tool that is used for identifying popularity metrics, general information about the business, finding similar products and competitors, and much more.

Watch it now at TrustRadar