healthhub.sg | Analytics by SecurityHeaders

HTTP Headers report for healthhub.sg

Header Name Header Data
HTTP status code 200
Set-Cookie shell#lang=en; path=/; secure; SameSite=None
Strict-Transport-Security max-age=31536000; includeSubDomains
Content-Security-Policy default-src 'self' https://secure-ds.serving-sys.com *.healthhub.sg https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' data: *.healthhub.sg https://ads-engagement.presage.io https://platform.twitter.com https://www.clarity.ms https://analytics.tiktok.com *.qualtrics.com *.google-analytics.com *.analytics.google.com https://sp.analytics.yahoo.com/ https://tr.outbrain.com/ https://vimeo.com/ https://www.vimeo.com/ cdn.taboola.com/ trc.taboola.com/ https://amplify.outbrain.com/ https://s.yimg.com/ https://s.ytimg.com/ https://www.youtube.com https://tagmanager.google.com http://www.google-analytics.com https://googleads.g.doubleclick.net https://www.googleadservices.com https://www.gstatic.com https://www.google-analytics.com https://www.googletagmanager.com https://www.google.com https://secure-ds.serving-sys.com https://bs.serving-sys.com https://connect.facebook.net/ https://servedby.revive-adserver.net https://*.hotjar.com https://secure.quantserve.com https://wave.outbrain.com https://rules.quantcount.com https://www.presage.io/; img-src 'self' data: https://servedby.revive-adserver.net/ *.healthhub.sg *.qualtrics.com *.google-analytics.com *.analytics.google.com https://www.googletagmanager.com https://cds.taboola.com/ https://www.gstatic.com https://ssl.gstatic.com https://tr.outbrain.com https://tagmanager.google.com https://developers.onemap.sg https://maps-a.onemap.sg https://maps-b.onemap.sg https://maps-c.onemap.sg https://s3-ap-southeast-1.amazonaws.com https://s3.amazonaws.com https://cm.g.doubleclick.net https://www.google.com.sg http://www.healthhub.sg https://www.google.com https://stats.g.doubleclick.net https://img.youtube.com https://maps.gstatic.com https://www.google-analytics.com https://app.sttarter.com:9000 https://ssl.sttarter.com:9000 http://app.sttarter.com:9000 http://ssl.sttarter.com:9000 https://ssl.sttarter.com:9443 https://facebook.com https://cdn.revive-adserver.net https://www.facebook.com https://ad.doubleclick.net https://sp.analytics.yahoo.com https://connect.facebook.net https://pixel.quantserve.com https://*.clarity.ms https://c.bing.com https://*.hotjar.com https://googleads.g.doubleclick.net https://ads-engagement.presage.io https://www.presage.io/; style-src 'self' 'unsafe-inline' *.healthhub.sg https://servedby.revive-adserver.net/ https://tagmanager.google.com https://fonts.googleapis.com https://fonts.gstatic.com https://*.hotjar.com; font-src 'self' *.healthhub.sg https://fonts.gstatic.com data: fonts.googleapis.com https://*.hotjar.com; connect-src 'self' *.healthhub.sg *.qualtrics.com *.google-analytics.com *.analytics.google.com https://www.google.com/ https://www.google-analytics.com https://stats.g.doubleclick.net/ https://trc-events.taboola.com/ https://vimeo.com/ https://www.vimeo.com/ https://www.facebook.com/ https://analytics.google.com/ https://prodigious.imailxpress.com https://trc.taboola.com/ https://s.yimg.com/ https://tagmanager.google.com https://www.healthhub.sg http://www.healthhub.sg secure-ds.serving-sys.com https://servedby.revive-adserver.net https://tr.outbrain.com https://pips.taboola.com https://cds.taboola.com https://analytics.tiktok.com https://*.clarity.ms https://pixel.quantcount.com https://www.google.com.sg https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com; frame-src 'self' *.healthhub.sg https://players.brightcove.net https://brightcove.net *.qualtrics.com https://9248167.fls.doubleclick.net/ https://www.player.vimeo.com/ https://www.vimeo.com/ https://player.vimeo.com/ https://vimeo.com/ web.facebook.com connect.facebook.net https://8416677.fls.doubleclick.net https://www.youtube.com https://tags.tiqcdn.com https://bid.g.doubleclick.net https://www.youtube.com https://syndication.twitter.com https://platform.twitter.com https://www.google.com https://fork.gotrackier.com https://view.officeapps.live.com https://*.doubleclick.net https://public.synapxe-ai.sg
X-Frame-Options DENY
X-Content-Type-Options nosniff
X-Cdn Imperva
X-Iinfo 14-24107975-24107977 NNNN CT(167 170 0) RT(1745068663222 3) q(0 0 4 19) r(5 7) U24
Date Sat, 19 Apr 2025 13:17:43 GMT
Cache-Control no-cache, no-store
Pragma no-cache
Content-Type text/html; charset=utf-8
Connection keep-alive
Expires -1
Vary Accept-Encoding
X-Xss-Protection 1; mode=block
Request-Context appId=cid-v1:f14695b8-7983-403c-9a53-64825ffa8acd
Accept-Ch Sec-CH-UA-Full-Version-List,Sec-CH-UA-Platform-Version,Sec-CH-UA-Arch,Sec-CH-UA-Model,Sec-CH-UA-Bitness

About the tool

By using SecurityHeaders.info, you can quickly identify missing or misconfigured headers and take steps to secure your website, improving both security and user confidence.

This tool is widely used by developers, security professionals, and organizations to ensure their websites adhere to best practices in web security.

We also have another analytic tool that is used for identifying popularity metrics, general information about the business, finding similar products and competitors, and much more.

Watch it now at TrustRadar