f1000.com | Analytics by SecurityHeaders

HTTP Headers report for f1000.com

Header Name Header Data
HTTP status code 200
Referrer-Policy no-referrer-when-downgrade
Strict-Transport-Security max-age=63072000; includeSubDomains
X-Content-Type-Options nosniff
X-Frame-Options SAMEORIGIN
Connection keep-alive
Link <https://www.f1000.com/wp-json/>; rel="https://api.w.org/"
X-Cacheable SHORT
Content-Security-Policy default-src https: 'self' 'unsafe-eval' 'unsafe-inline' https://*.onetrust.com/ https://*.cookielaw.org/ https://cdn.linkedin.oribi.io https://secure.scan6show.com/ https://secure.diet3dart.com/ https://*.addtoany.com https://*.ads-twitter.com https://*.adsymptotic.com https://*.advancedcustomfields.com https://*.akamaihd.net https://*.altmetric.com https://*.baidu.com https://*.bizographics.com https://*.bootstrapcdn.com https://*.buzzsprout.com https://*.canva.com https://*.cloudflare.com https://*.cloudflareinsights.com https://*.cloudfront.net https://*.cnzz.com https://*.doubleclick.net https://*.facebook.com https://*.facebook.net https://*.fontawesome.com https://*.formstack.com https://*.fullstory.com https://*.github.io https://*.google-analytics.com https://*.google.be https://*.google.co.uk https://*.google.com https://*.googleadservices.com https://*.googleapis.com https://*.googleoptimize.com https://*.googletagmanager.com https://*.googleusercontent.com https://*.gravatar.com https://*.gravityforms.com https://*.gravityforms.local https://*.gstatic.com https://*.hotjar.com https://*.hotjar.io https://*.imagify.io https://*.jquery.com https://*.jsdelivr.net https://*.licdn.com https://*.linkedin.com https://*.netdna-ssl.com https://*.newrelic.com https://*.pardot.com https://*.paypalobjects.com https://*.ravenjs.com https://*.sharethis.com https://*.soundcloud.com https://*.tablepress.org https://*.tandf.co.uk https://*.tandfonline.com https://*.taylorandfrancis.com https://*.thinglink.com https://*.twimg.com https://*.twitter.com https://*.typekit.net https://*.vimeo.com https://*.w.org https://*.wistia.com https://*.wp.com https://*.wpengine.co.uk https://*.wpengine.com https://*.wpengineapi.com https://*.wpmudev.org https://*.yoast.com https://*.youku.com https://*.youtube.com https://*.yumpu.com https://abc123-wpengine.netdna-ssl.com https://bam.eu01.nr-data.net https://cnzz.mmstat.com https://i.ytimg.com https://imagify.io https://placehold.it https://t.co https://tandfapi.co.uk https://web-player.art19.com https://wpengine.com https://wpmudev.com https://yoast.com; font-src https: 'self' data: ; img-src * 'self' data: blob: ; worker-src https: 'self' blob: ;
X-Xss-Protection 1; mode=block
Server cloudflare
Cf-Ray 92c91a6f6b4b668c-AMS
Vary Accept-Encoding
X-Powered-By WP Engine
Access-Control-Allow-Origin *
Permissions-Policy accelerometer=self, autoplay=self, camera=self, display-capture=self, document-domain=self, fullscreen=self, geolocation=self, gyroscope=self, magnetometer=self, microphone=self, midi=self, payment=self, picture-in-picture=self, sync-xhr=self, usb=self, screen-wake-lock=self, xr-spatial-tracking=self
Alt-Svc h3=":443"; ma=86400
Date Mon, 07 Apr 2025 11:14:46 GMT
Cache-Control max-age=600, must-revalidate
X-Cache HIT: 1
Content-Type text/html; charset=UTF-8
X-Cache-Group normal
Cf-Cache-Status DYNAMIC

About the tool

By using SecurityHeaders.info, you can quickly identify missing or misconfigured headers and take steps to secure your website, improving both security and user confidence.

This tool is widely used by developers, security professionals, and organizations to ensure their websites adhere to best practices in web security.

We also have another analytic tool that is used for identifying popularity metrics, general information about the business, finding similar products and competitors, and much more.

Watch it now at TrustRadar