mcmc.gov.my | Analytics by SecurityHeaders

HTTP Headers report for mcmc.gov.my

Header Name Header Data
HTTP status code 200
Accept-Ch Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA
Cross-Origin-Opener-Policy same-origin
Vary Accept-Encoding
X-Xss-Protection 1; mode=block
Content-Security-Policy default-src * data: mediastream: blob: filesystem: about: ws: wss: 'wasm-unsafe-eval' 'unsafe-inline' 'unsafe-eval';
X-Frame-Options SAMEORIGIN
Cross-Origin-Resource-Policy same-origin
Strict-Transport-Security max-age=31536000; includeSubDomains; preload
Date Sun, 20 Apr 2025 07:35:03 GMT
Cf-Mitigated challenge
X-Content-Type-Options nosniff
Cache-Control private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Expires Thu, 01 Jan 1970 00:00:01 GMT
Cross-Origin-Embedder-Policy-Report-Only (unsafe-none|require-corp); report-to="default"
Set-Cookie HttpOnly; Secure;
Content-Type text/html; charset=UTF-8
Origin-Agent-Cluster ?1
Permissions-Policy geolocation=(*), accelerometer=(),autoplay=(*),camera=(),clipboard-read=(),clipboard-write=(),gyroscope=(),microphone=(),payment=(),publickey-credentials-get=(),screen-wake-lock=(),serial=(),sync-xhr=(),usb=()
Frame-Ancestors *
Script-Src * 'unsafe-eval' 'unsafe-inline'
Cf-Ray 9332f674bba78645-AMS
Server-Timing chlray;desc="9332f674bba78645"
X-Content-Options nosniff
Referrer-Policy same-origin
Server cloudflare
Critical-Ch Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA
Cross-Origin-Embedder-Policy require-corp
Expect-Ct max-age=86400, enforce
Alt-Svc h3=":443"; ma=86400

About the tool

By using SecurityHeaders.info, you can quickly identify missing or misconfigured headers and take steps to secure your website, improving both security and user confidence.

This tool is widely used by developers, security professionals, and organizations to ensure their websites adhere to best practices in web security.

We also have another analytic tool that is used for identifying popularity metrics, general information about the business, finding similar products and competitors, and much more.

Watch it now at TrustRadar