Header Name | Header Data |
---|---|
HTTP status code | 200 |
X-Xss-Protection | 1; mode=block |
Accept-Ranges | bytes |
X-Served-By | cache-yyz4579-YYZ, cache-yyz4570-YYZ, cache-lcy-eglc8600024-LCY |
X-Cache-Hits | 0, 6, 0 |
Connection | keep-alive |
Report-To | {"group":"report-endpoint","max_age":10886400,"endpoints":[{"url":"https:\/\/3706dfdc-3ec8-4812-add5-b403178623a6.sansec.watch\/"}]} |
X-Debug-Info | eyJyZXRyaWVzIjowfQ== |
X-Frame-Options | SAMEORIGIN |
Strict-Transport-Security | max-age=31557600 |
X-Akamai-Transformed | 9 50536 0 pmb=mRUM,2 |
Expires | Mon, 07 Apr 2025 17:01:46 GMT |
Cache-Control | max-age=0, no-cache, no-store |
Traceresponse | 00-1833cc301e41fd186268c6fb6862c7a2-78ebc22478718ba9-01 |
Content-Type | text/html; charset=UTF-8 |
Pragma | no-cache |
Date | Mon, 07 Apr 2025 17:01:46 GMT |
Server-Timing | cdn-cache; desc=MISS |
X-Country | NL |
X-Content-Type-Options | nosniff |
X-Timer | S1743961988.755348,VS0,VE404 |
Vary | Accept-Encoding,Cookie |
X-Platform-Server | i-0a86c3b9f1672a561 |
Content-Security-Policy | font-src fonts.gstatic.com use.typekit.net *.omds.acidgreen.com.au *.explore.omsystem.com *.fontawesome.com fonts.googleapis.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.omds.acidgreen.com.au *.explore.omsystem.com cl.s51.exct.net *.adyen.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com *.omds.acidgreen.com.au *.explore.omsystem.com *.adyen.com *.google.com/ instafeed.pixlee.co photos.pixlee.co *.addthis.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com p.typekit.net validator.swagger.io *.omds.acidgreen.com.au *.explore.omsystem.com explore.omsystem.com blob: *.getolympus.com *.akstat.io *.cookielaw.org *.ggpht.com https://www.magezon.com *.bing.com *.bing.net *.criteo.com *.doubleclick.net *.elfsightcdn.com *.facebook.com *.facebook.net *.google.com *.googleapis.com *.googletagmanager.com *.gstatic.com *.igodigital.com *.mczbf.com *.olympus.eu *.omappapi.com *.pricespider.com google.com www.google.ad www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bg www.google.bj www.google.bs www.google.bt www.google.by www.google.ca www.google.cf www.google.ch www.google.ci www.google.cl www.google.co.ao www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ls www.google.co.ma www.google.co.mz www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.vi www.google.co.za www.google.co.zm www.google.co.zw www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bn www.google.com.bo www.google.com.br www.google.com.bz www.google.com.co www.google.com.cu www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.fj www.google.com.gi www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.ni www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.sl www.google.com.sv www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vc www.google.com.vn www.google.cv www.google.cz www.google.de www.google.dj www.google.dk www.google.dz www.google.ee www.google.es www.google.fi www.google.fm www.google.fr www.google.ge www.google.gg www.google.gl www.google.gr www.google.gy www.google.hn www.google.hr www.google.hu www.google.ie www.google.im www.google.iq www.google.is www.google.it www.google.je www.google.jo www.google.kg www.google.kz www.google.la www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.mn www.google.mu www.google.mv www.google.nl www.google.no www.google.pl www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.sc www.google.se www.google.si www.google.sk www.google.sm www.google.sr www.google.tn www.google.tt www.google.vu https://id5-sync.com https://tg.socdm.com https://cs.adingo.jp https://ads.stickyadstv.com https://idsync.rlcdn.com https://exchange.mediavine.com https://jadserve.postrelease.com https://criteo-partners.tremorhub.com https://ad.yieldlab.net https://x.bidswitch.net https://ib.adnxs.com https://r.casalemedia.com https://ad.360yield.com https://contextual.media.net https://sync.outbrain.com https://simage2.pubmatic.com https://pixel.rubiconproject.com https://rtb-csync.smartadserver.com https://sync-t1.taboola.com https://criteo-sync.teads.tv https://eb2.3lift.com https://aa.agkn.com https://ade.clmbtech.com https://sync.1rx.io *.adyen.com maps.googleapis.com maps.gstatic.com *.pxlecdn.com *.pixlee.com *.cdninstagram.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com beacon-qa.magento-datasolutions.com beacon-stage.magento-ds.com beacon.magento-ds.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net www.googletagmanager.com *.cash.app *.payments-amazon.com *.google.com *.paypal.com *.checkout.visa.com *.mastercard.com *.omds.acidgreen.com.au *.explore.omsystem.com *.go-mpulse.net *.newrelic.com *.cookielaw.org *.weglot.com *.pricespider.com cdnjs.cloudflare.com api.tiles.mapbox.com *.adobedtm.com *.bing.com *.criteo.com *.doubleclick.net *.elfsight.com *.facebook.net *.googleapis.com *.googletagmanager.com *.igodigital.com *.mczbf.com *.omappapi.com *.pixlee.com *.js-agent.newrelic.com *.bam.nr-data.net *.cardinalcommerce.com *.adyen.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.google.com/ *.marketo.com *.pxlecdn.com *.pixlee.co assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.omds.acidgreen.com.au *.explore.omsystem.com *.weglot.com *.fontawesome.com api.tiles.mapbox.com *.omappapi.com *.pricespider.com *.gstatic.com *.marketo.com assets.pixlee.com *.addthis.com *.moatads.com *.addthisedge.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.googleapis.com *.gstatic.com https://cdn.pubble.io 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com *.snplow.net commerce.adobedc.net p13n-mr.adobe.io www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobedc.net *.demdex.net *.adobe.io performance.typekit.net *.sentry.io *.omds.acidgreen.com.au *.explore.omsystem.com *.akamaihd.net *.akstat.io *.go-mpulse.net *.cookielaw.org *.weglot.com cdn-api-weglot.com *.bing.com *.bing.net *.criteo.com *.doubleclick.net *.elfsight.com *.facebook.com *.google.com *.googleapis.com *.gstatic.com *.mczbf.com *.mapbox.com *.omappapi.com *.onetrust.com *.pricespider.com *.pixlee.com *.bam.nr-data.net *.js-agent.newrelic.com https://getolympus.registria.com *.adyen.com https://maps.googleapis.com bam.nr-data.net *.marketo.com *.addthis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://3706dfdc-3ec8-4812-add5-b403178623a6.sansec.watch/; report-to report-endpoint; |
By using SecurityHeaders.info, you can quickly identify missing or misconfigured headers and take steps to secure your website, improving both security and user confidence.
This tool is widely used by developers, security professionals, and organizations to ensure their websites adhere to best practices in web security.
We also have another analytic tool that is used for identifying popularity metrics, general information about the business, finding similar products and competitors, and much more.
Watch it now at TrustRadar