marketplace.visualstudio.com | Analytics by SecurityHeaders

HTTP Headers report for marketplace.visualstudio.com

Header Name Header Data
HTTP status code 200
Request-Context appId=cid-v1:84715e31-583a-4723-a46d-946169b2f4a8
X-Content-Type-Options nosniff
Pragma no-cache
Content-Type text/html; charset=utf-8
P3p CP="CAO DSP COR ADMa DEV CONo TELo CUR PSA PSD TAI IVDo OUR SAMi BUS DEM NAV STA UNI COM INT PHY ONL FIN PUR LOC CNT"
Set-Cookie VstsSession=%7B%22PersistentSessionId%22%3A%223175a6b8-5d7c-442f-9441-029e15e0f5ae%22%2C%22PendingAuthenticationSessionId%22%3A%2200000000-0000-0000-0000-000000000000%22%2C%22CurrentAuthenticationSessionId%22%3A%2200000000-0000-0000-0000-000000000000%22%2C%22SignInState%22%3A%7B%7D%7D;SameSite=None; domain=.visualstudio.com; expires=Tue, 07-Apr-2026 11:05:24 GMT; path=/; secure; HttpOnly
Access-Control-Expose-Headers Request-Context
X-Msedge-Ref Ref A: 54A0C87C26B0418CB6BC21E37B2122C9 Ref B: AMS04EDGE3222 Ref C: 2025-04-07T11:05:24Z
Expires -1
X-Tfs-Session ed70a3fc-9e06-4cfb-989f-36e7922f5548
X-Frame-Options SAMEORIGIN
X-Cache CONFIG_NOCACHE
Vary Accept-Encoding
Activityid ed70a3fc-9e06-4cfb-989f-36e7922f5548
X-Vss-Senderdeploymentid 2663b13f-50e3-a655-a159-22f6f4725fab
Content-Security-Policy default-src 'none'; base-uri 'none'; font-src *.visualstudio.com *.dev.azure.com dev.azure.com *.vsassets.io vsassetscdn.azure.cn *.microsoft.com *.sharepointonline.com *.s-microsoft.com; style-src 'unsafe-inline' *.visualstudio.com *.dev.azure.com dev.azure.com cdn.vsassets.io vsassetscdn.azure.cn *.s-microsoft.com; connect-src *.visualstudio.com wss://*.visualstudio.com *.dev.azure.com dev.azure.com wss://*.dev.azure.com wss://dev.azure.com *.vsassets.io vsassetscdn.azure.cn *.blob.core.windows.net *.github.com web.vortex.data.microsoft.com dpm.demdex.net https://login.microsoftonline.com; img-src http: https: blob: data:; script-src 'unsafe-inline' *.visualstudio.com *.dev.azure.com dev.azure.com https://cdn.vsassets.io https://vsassetscdn.azure.cn *.ensighten.com *.microsoft.com *.google-analytics.com az725175.vo.msecnd.net *.s-microsoft.com *.googletagmanager.com *.google.com 'nonce-7WelgxWLQsv+R9/Qjlrh0A=='; child-src * blob: tfs:; frame-src * blob: tfs:; worker-src * blob: tfs:; media-src http: https:;
X-Vss-E2eid ed70a3fc-9e06-4cfb-989f-36e7922f5548
Date Mon, 07 Apr 2025 11:05:24 GMT
Cache-Control no-cache, no-store, must-revalidate
X-Tfs-Processid 331a9e57-2215-466d-a293-3ce5c0be85bb
Strict-Transport-Security max-age=31536000; includeSubDomains

About the tool

By using SecurityHeaders.info, you can quickly identify missing or misconfigured headers and take steps to secure your website, improving both security and user confidence.

This tool is widely used by developers, security professionals, and organizations to ensure their websites adhere to best practices in web security.

We also have another analytic tool that is used for identifying popularity metrics, general information about the business, finding similar products and competitors, and much more.

Watch it now at TrustRadar