cityofmadison.com | Analytics by SecurityHeaders

HTTP Headers report for cityofmadison.com

Header Name Header Data
HTTP status code 200
X-Request-Id v-36ecc672-1cbd-11f0-b507-6f21af231378
Server nginx
Cache-Control max-age=31536000, public
Content-Language en
X-Content-Type-Options nosniff
Vary Cookie,Origin,Accept-Encoding
Strict-Transport-Security max-age=1000
X-Ah-Environment prod
Age 247
Date Sat, 19 Apr 2025 01:29:52 GMT
X-Cache-Hits 17
Connection keep-alive
Content-Security-Policy default-src 'self'; script-src 'self' 'unsafe-inline' *.cloudflare.com *.facebook.net *.googletagmanager.com js.arcgis.com *.jsdelivr.net maps.googleapis.com *.newrelic.com *.recollect.net *.siteimprove.net siteimproveanalytics.com ui.customsearch.ai unpkg.com *.wisconsin.gov; style-src 'self' 'unsafe-inline' *.cloudflare.com fonts.googleapis.com js.arcgis.com *.jsdelivr.net recollect.a.ssl.fastly.net unpkg.com *.windows.net; img-src 'self' data: *.arcgis.com *.google-analytics.com *.googletagmanager.com maps.googleapis.com maps.gstatic.com recollect.a.ssl.fastly.net recollect-images.global.ssl.fastly.net *.recollect.net *.siteimproveanalytics.io *.windows.net; frame-src 'self' app.powerbigov.us bi.wisconsin.gov cityofmadison.maps.arcgis.com *.cityofmadison.com *.facebook.com *.google.com *.publichealthmdc.com *.recollect.net storymaps.arcgis.com *.youtube.com *.siteimprove.com; frame-ancestors 'self'; child-src 'self' blob: app.powerbigov.us bi.wisconsin.gov cityofmadison.maps.arcgis.com *.cityofmadison.com *.facebook.com *.google.com *.publichealthmdc.com *.recollect.net storymaps.arcgis.com *.youtube.com; font-src 'self' fonts.gstatic.com recollect.a.ssl.fastly.net; connect-src 'self' *.arcgis.com *.arcgisonline.com *.google-analytics.com js.arcgis.com maps.cityofmadison.com maps.googleapis.com *.nr-data.net *.siteimprove.com *.siteimproveanalytics.com ui.customsearch.ai; report-uri /report-csp-violation; upgrade-insecure-requests
X-Drupal-Cache HIT
Etag "1745025942-gzip"
Via varnish
X-Cache HIT
Content-Type text/html; charset=UTF-8
X-Drupal-Dynamic-Cache UNCACHEABLE (poor cacheability)
Expires Sun, 19 Nov 1978 05:00:00 GMT
X-Generator Drupal 10 (https://www.drupal.org)
Referrer-Policy no-referrer-when-downgrade
Last-Modified Sat, 19 Apr 2025 01:25:42 GMT
Accept-Ranges bytes

About the tool

By using SecurityHeaders.info, you can quickly identify missing or misconfigured headers and take steps to secure your website, improving both security and user confidence.

This tool is widely used by developers, security professionals, and organizations to ensure their websites adhere to best practices in web security.

We also have another analytic tool that is used for identifying popularity metrics, general information about the business, finding similar products and competitors, and much more.

Watch it now at TrustRadar