carto.com | Analytics by SecurityHeaders

HTTP Headers report for carto.com

Header Name Header Data
HTTP status code 200
Strict-Transport-Security max-age=31536000; includeSubDomains
Cf-Ray 92d6788769f907a4-IAD
X-Cluster-Name us-east-1-prod-hosting-red
Referrer-Policy strict-origin-when-cross-origin
Last-Modified Tue, 08 Apr 2025 14:45:32 GMT
Alt-Svc h3=":443"; ma=86400
Surrogate-Key webflow.carto.com 6345207a1b18e581fcf67604 pageId:65e9f2a5aa591b41d23fcc95 65e9f2a5aa591b41d23fcc9a 65e9f2a5aa591b41d23fccab
Vary Accept-Encoding
X-Content-Type-Options nosniff
Cross-Origin-Resource-Policy cross-origin
Content-Security-Policy upgrade-insecure-requests
Via 1.1 google
Cf-Cache-Status HIT
Age 41123
Cache-Control public
Cross-Origin-Embedder-Policy unsafe-none
Date Wed, 09 Apr 2025 02:10:55 GMT
X-Lambda-Id d37152be-a0e0-45d2-856a-7535338e7122
Content-Type text/html
Set-Cookie _cfuvid=C7ZV9PrVZ4zUhY2WSDOBZcGzhUBXJLAX1xhWBavJlx0-1744164655315-0.0.1.1-604800000; path=/; domain=.cdn.webflow.com; HttpOnly; Secure; SameSite=None
Permissions-Policy accelerometer=(), autoplay=(), camera=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), publickey-credentials-get=(), screen-wake-lock=(), usb=()
Cross-Origin-Opener-Policy unsafe-none
Surrogate-Control max-age=432000
X-Frame-Options DENY

About the tool

By using SecurityHeaders.info, you can quickly identify missing or misconfigured headers and take steps to secure your website, improving both security and user confidence.

This tool is widely used by developers, security professionals, and organizations to ensure their websites adhere to best practices in web security.

We also have another analytic tool that is used for identifying popularity metrics, general information about the business, finding similar products and competitors, and much more.

Watch it now at TrustRadar