louvre.fr | Analytics by SecurityHeaders

HTTP Headers report for louvre.fr

Header Name Header Data
HTTP status code 200
Cross-Origin-Resource-Policy same-origin
Etag W/"h3ktoq08ps77l4"
Access-Control-Allow-Origin https://www.louvre.fr
Permissions-Policy fullscreen=(self "https://www.youtube.com" "https://player.vimeo.com" "https://livemap.getwemap.com"),geolocation=(self "https://livemap.getwemap.com")
Cross-Origin-Opener-Policy same-origin
Content-Length 337114
Connection keep-alive
Link <https://api-www.louvre.fr>; rel="preconnect"
Accept-Ranges bytes
Date Sat, 05 Apr 2025 08:19:44 GMT
Content-Type text/html; charset=utf-8
Access-Control-Allow-Methods GET, OPTIONS
Access-Control-Allow-Headers Origin, Accept, Content-Type, X-Requested-With, X-CSRF-Token, Authorization, Access-Control-Allow-Origin, Req.Http.Origin, Cors
X-Wadp-Ttl 309.973
X-Clara-Wadp 59286912 64990231
Document-Policy document-write=?0
X-Dns-Prefetch-Control off
X-Content-Type-Options nosniff
X-Frame-Options DENY
X-Wadp-Age 290.667
X-Wadp-Cache HIT
Content-Security-Policy default-src 'self' https://api-www.louvre.fr;base-uri 'self';style-src 'self' 'unsafe-inline' https://fonts.googleapis.com;script-src 'self' 'strict-dynamic' 'unsafe-inline' https://tag.aticdn.net https://www.youtube.com 'nonce-44238434-cebd-419f-8d2e-eae3979e5469';img-src 'self' data: https://api-www.louvre.fr https://i.ytimg.com https://i.vimeocdn.com;media-src 'self' https://api-www.louvre.fr https://*.ausha.co https://*.radiofrance-podcast.net;connect-src 'self' https://api-www.louvre.fr fxxslpn.pa-cd.com;frame-src https://www.youtube.com https://player.vimeo.com https://livemap.getwemap.com https://embed.radiofrance.fr/;frame-ancestors 'none';form-action 'self' https://api-www.louvre.fr;manifest-src 'self';font-src 'self' https://fonts.gstatic.com;object-src 'none';upgrade-insecure-requests
X-Cache-Hits 9719
Referrer-Policy strict-origin-when-cross-origin
Cache-Control max-age=600
Server wadp2
Feature-Policy geolocation 'none'
X-Download-Options noopen
X-Xss-Protection 0
Age 9081
Expect-Ct max-age=0
X-Permitted-Cross-Domain-Policies none
Strict-Transport-Security max-age=15552000; includeSubDomains
X-Cache HIT

About the tool

By using SecurityHeaders.info, you can quickly identify missing or misconfigured headers and take steps to secure your website, improving both security and user confidence.

This tool is widely used by developers, security professionals, and organizations to ensure their websites adhere to best practices in web security.

We also have another analytic tool that is used for identifying popularity metrics, general information about the business, finding similar products and competitors, and much more.

Watch it now at TrustRadar