jewishla.org | Analytics by SecurityHeaders

HTTP Headers report for jewishla.org

Header Name Header Data
HTTP status code 200
Content-Security-Policy base-uri 'self'; default-src 'self'; script-src 'nonce-97d9f2f0e8' 'unsafe-inline' 'unsafe-eval' 'self' https: *.googletagmanager.com *.google.com *.sharethis.com code.jquery.com *.fontawesome.com dev-jewishlatest.pantheonsite.io test-jewishlatest.pantheonsite.io live-jewishlatest.pantheonsite.io connect.facebook.net; script-src-elem 'self' https: 'unsafe-inline' *.googletagmanager.com *.google.com code.jquery.com *.fontawesome.com; style-src 'self' 'unsafe-inline' careers-content.clearcompany.com *.typekit.net *.jotfor.ms *.googleapis.com; font-src 'self' fonts.googleapis.com *.bootstrapcdn.com *.fontawesome.com *.typekit.net fonts.gstatic.com *.surveygizmo.com *.jotfor.ms data:; media-src 'self' blob: data:; img-src 'self' careers-content.clearcompany.com maps.googleapis.com maps.gstatic.com 47156la.blackbaudhosting.com *.facebook.com *.fbcdn.net *.jotform.com cdn.jotfor.ms *.g.doubleclick.net *.googlesyndication.com *.google.com *.google-analytics.com *.googletagmanager.com googleads.g.doubleclick.net *.jewishla.org jewishla.org *.surveygizmo.com data: w3.org/svg/2000; form-action 'self' *.jotform.com *.facebook.com *.surveygizmo.com *.alchemer.com; object-src 'none'; worker-src 'self' blob:; frame-src 'self' *.doubleclick.net *.g.doubleclick.net *.google.com *.googletagmanager.com *.googlesyndication.com *.jotform.com *.idonate.com *.facebook.com *.facebook.net *.vimeo.com *.youtube.com *.youtu.be *.alchemer.com; child-src 'self' bam.nr-data.net *.google.com *.doubleclick.net googleads.g.doubleclick.net *.googletagmanager.com *.vimeo.com *.youtube.com *.youtu.be *.idonate.com *.libsyn.com *.jotform.com widgets.jotform.io *.facebook.com www.jewishla.org/wp-content/themes/blockbase/php-templates/content-job_jotform.php www.jewishla.org/wp-content/themes/blockbase/php-templates/content-signup_general.php www.jewishla.org/wp-content/themes/blockbase/php-templates/content-signup_google.php; connect-src 'self' careers-content.clearcompany.com careers-api.clearcompany.com maps.googleapis.com *.googlesyndication.com *.g.doubleclick.net googleads.g.doubleclick.net *.doubleclick.net *.google-analytics.com www.googletagmanager.com www.google.com analytics.google.com/g/collect www.google.com/ccm/collect *.facebook.com *.facebook.net bam.nr-data.net *.sharethis.com *.fontawesome.com *.idonate.com www.jewishla.org/index.php/wp-json/tribe/views/v2/html jewishla.org/index.php/wp-json/tribe/views/v2/html; report-uri /csp-report.php
Content-Type text/html; charset=UTF-8
Link <https://www.jewishla.org/index.php/wp-json/>; rel="https://api.w.org/"
Accept-Ranges bytes
Date Thu, 17 Apr 2025 16:44:24 GMT
Cache-Control public, max-age=2592000
X-Frame-Options SAMEORIGIN
X-Xss-Protection 1; mode=block
X-Pantheon-Styx-Hostname styx-fe4-a-5f5496676d-dhzl9
X-Tec-Api-Origin https://www.jewishla.org
X-Cache HIT, HIT, MISS, MISS
X-Cache-Hits 30, 0, 0, 0
X-Timer S1744908264.195222,VS0,VE13
X-Tec-Api-Version v1
Connection keep-alive
Server nginx
Strict-Transport-Security max-age=300
X-Content-Type nosniff
X-Styx-Req-Id e303ffc5-1ba6-11f0-8a83-96861a096ff5
X-Tec-Api-Root https://www.jewishla.org/index.php/wp-json/tribe/events/v1/
Age 1858
Via 1.1 varnish, 1.1 varnish, 1.1 varnish, 1.1 varnish
X-Served-By cache-chi-kigq8000109-CHI, cache-ams21056-AMS, cache-ams2100121-AMS, cache-ams2100121-AMS
Vary Accept-Encoding, Cookie, Cookie

About the tool

By using SecurityHeaders.info, you can quickly identify missing or misconfigured headers and take steps to secure your website, improving both security and user confidence.

This tool is widely used by developers, security professionals, and organizations to ensure their websites adhere to best practices in web security.

We also have another analytic tool that is used for identifying popularity metrics, general information about the business, finding similar products and competitors, and much more.

Watch it now at TrustRadar