innovasjonnorge.no | Analytics by SecurityHeaders

HTTP Headers report for innovasjonnorge.no

Header Name Header Data
HTTP status code 200
Date Sun, 20 Apr 2025 18:41:34 GMT
Vary RSC, Next-Router-State-Tree, Next-Router-Prefetch, Next-Router-Segment-Prefetch, Accept-Encoding
X-Xss-Protection 1; mode=block
X-Dns-Prefetch-Control on
X-Powered-By Next.js
Set-Cookie ARRAffinity=5d3bb0cc5314dac709ef8c057303b1115e3073c31d5785ae09471992006bd4ac;Path=/;HttpOnly;Secure;Domain=www.innovasjonnorge.no
X-Frame-Options SAMEORIGIN
X-Content-Type-Options nosniff
Link </_next/static/media/0f3a385557f1712f-s.p.woff2>; rel=preload; as="font"; crossorigin=""; type="font/woff2", </_next/static/media/47cbc4e2adbc5db9-s.p.woff2>; rel=preload; as="font"; crossorigin=""; type="font/woff2", </_next/static/css/4cd2526f7d896a4e.css>; rel=preload; as="style", </_next/static/css/037072834fffcc1e.css>; rel=preload; as="style", </_next/static/css/31c4d14f93a8674f.css>; rel=preload; as="style", </_next/static/css/c80868e919e02fad.css>; rel=preload; as="style"
Cf-Cache-Status DYNAMIC
Cf-Ray 9336c6cebe6966ff-AMS
Content-Type text/html; charset=utf-8
Connection keep-alive
Strict-Transport-Security max-age=63072000; includeSubDomains; preload
Referrer-Policy origin-when-cross-origin
Server cloudflare
Cache-Control private, no-cache, no-store, max-age=0, must-revalidate
Permissions-Policy camera=(), microphone=(), geolocation=()
Content-Security-Policy default-src 'self' 'unsafe-eval'; media-src 'self' cdn.sanity.io *.svc.dynamics.com *.mkt.dynamics.com; frame-ancestors 'self' localhost:3333 *.innovasjonnorge.no; frame-src 'self' player.acast.com embed.acast.com m365-prod-barekraft-dataverse-proxy.azurewebsites.net app.powerbi.com *.svc.dynamics.com *.mkt.dynamics.com *.youtube-nocookie.com *.youtube.com player.vimeo.com pixel.as plaii.no embed.plaii.no a6117309782163456.cdn.optimizely.com a6117309782163456.cdn-pci.optimizely.com; font-src 'self' res-1.cdn.office.net fonts.gstatic.com *.hotjar.com component-library-dev-cdn.azureedge.net inno-dev-cdn.azureedge.net; img-src 'self' data: *.svc.dynamics.com *.mkt.dynamics.com cdn.sanity.io maps.googleapis.com maps.gstatic.com www.facebook.com *.hotjar.com ssl.google-analytics.com stats.g.doubleclick.net *.siteimproveanalytics.io cdn.cookielaw.org cdn.optimizely.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.hotjar.com; script-src-elem 'self' 'unsafe-inline' m365-prod-barekraft-dataverse-proxy.azurewebsites.net *.svc.dynamics.com *.mkt.dynamics.com cdn.jsdelivr.net mktdplp102cdn.azureedge.net connect.facebook.net maps.googleapis.com player.vimeo.com s.ytimg.com www.youtube.com s7.addthis.com az416426.vo.msecnd.net ssl.google-analytics.com static.hotjar.com v1.addthis.com v1.addthisedge.com www.googletagmanager.com px.ads.linkedin.com script.hotjar.com snap.licdn.com siteimproveanalytics.com cdn.cookielaw.org plausible.io cxppusa1formui01cdnsa01-endpoint.azureedge.net https://*.optimizely.com https://optimizely.s3.amazonaws.com https://cdn-assets-prod.s3.amazonaws.com; style-src 'self' 'unsafe-inline' *.hotjar.com fonts.googleapis.com; style-src-elem 'self' 'unsafe-inline' m365-prod-barekraft-dataverse-proxy.azurewebsites.net fonts.googleapis.com addtocalendar.com; connect-src 'self' data.brreg.no m365-prod-barekraft-dataverse-proxy.azurewebsites.net *.svc.dynamics.com *.mkt.dynamics.com *.algolia.net *.algolianet.com *.algolia.io loal7n8w.api.sanity.io loal7n8w.apicdn.sanity.io s7.addthis.com v1.addthis.com www.facebook.com plausible.io cdn.cookielaw.org geolocation.onetrust.com *.hotjar.com *.hotjar.io wss://*.hotjar.com cxppusa1formui01cdnsa01-endpoint.azureedge.net privacyportal-eu.onetrust.com logx.optimizely.com *.optimizely.com; style-src-attr 'unsafe-inline';

About the tool

By using SecurityHeaders.info, you can quickly identify missing or misconfigured headers and take steps to secure your website, improving both security and user confidence.

This tool is widely used by developers, security professionals, and organizations to ensure their websites adhere to best practices in web security.

We also have another analytic tool that is used for identifying popularity metrics, general information about the business, finding similar products and competitors, and much more.

Watch it now at TrustRadar