heinz.com | Analytics by SecurityHeaders

HTTP Headers report for heinz.com

Header Name Header Data
HTTP status code 200
Etag "tt41cgiih6dsan"
Alt-Svc h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
Cache-Control s-maxage=180, stale-while-revalidate
Date Tue, 08 Apr 2025 02:43:28 GMT
Server Google Frontend
Strict-Transport-Security max-age=31536000; preload
Vary Accept-Encoding
Content-Security-Policy-Report-Only script-src 'self' 'unsafe-inline' 'unsafe-eval' cdn.jsdelivr.net *.lytics.io *.customer.io www.googletagmanager.com www.googleoptimize.com maps.googleapis.com www.gstatic.com *.hotjar.com *.privacymanager.io *.onetrust.com polyfill.io *.bytedapm.com *.ttwstatic.com www.tiktok.com *.tiktokcdn-us.com *.pricespider.com *.swaven.com *.static-swaven.com edge.marker.io login.dotomi.com sc-static.net; report-uri https://o4504005838045184.ingest.sentry.io/api/4505410929033216/security/?sentry_key=14a5b105c2c7443983e52fe24209ded4
Permissions-Policy camera=(), display-capture=(), fullscreen=(), geolocation=(), microphone=()
Content-Type text/html; charset=utf-8
Via 1.1 google
X-Frame-Options SAMEORIGIN
Content-Language en
Set-Cookie kh-preferred-locale=en-US; Path=/; Expires=Wed, 08 Apr 2026 02:43:28 GMT
X-Nextjs-Cache HIT
X-Powered-By Next.js
Referrer-Policy strict-origin-when-cross-origin
X-Content-Type-Options nosniff
X-Cache-Hit miss

About the tool

By using SecurityHeaders.info, you can quickly identify missing or misconfigured headers and take steps to secure your website, improving both security and user confidence.

This tool is widely used by developers, security professionals, and organizations to ensure their websites adhere to best practices in web security.

We also have another analytic tool that is used for identifying popularity metrics, general information about the business, finding similar products and competitors, and much more.

Watch it now at TrustRadar