nav.no | Analytics by SecurityHeaders

HTTP Headers report for nav.no

Header Name Header Data
HTTP status code 200
Content-Type text/html; charset=utf-8
X-Nextjs-Cache HIT
Etag "1482wkf4z7v1j7b"
Strict-Transport-Security max-age=31536000; includeSubDomains; preload
Alt-Svc h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
Set-Cookie BIGipServerpool_pr_gcp_navno_lb_https=!JHLxKuq1SoiM15BegOeYibg2bW6N6OQXqPpiL2yvkWnvr0lzN41fkvPBi15UEKB3C+1DTrtigglYTQ==; path=/; Httponly; Secure
X-Powered-By Next.js
Content-Security-Policy default-src *.nav.no portal-admin.oera.no; script-src *.nav.no portal-admin.oera.no *.tingtun.no termer.no widget.uxsignals.com *.skyra.no *.psplugin.com *.hotjar.com *.taskanalytics.com nav.boost.ai 'unsafe-inline' 'unsafe-eval'; script-src-elem *.nav.no portal-admin.oera.no *.tingtun.no termer.no widget.uxsignals.com *.skyra.no video.qbrick.com play2.qbrick.com analytics.qbrick.com *.ip-only.net blob: *.psplugin.com *.hotjar.com *.taskanalytics.com nav.boost.ai 'unsafe-inline'; worker-src *.nav.no portal-admin.oera.no blob:; style-src *.nav.no portal-admin.oera.no 'unsafe-inline' *.psplugin.com *.googleapis.com *.gstatic.com; font-src *.nav.no portal-admin.oera.no data: video.qbrick.com play2.qbrick.com analytics.qbrick.com *.ip-only.net blob: *.psplugin.com *.hotjar.com *.skyra.no cdn.nav.no *.googleapis.com *.gstatic.com; img-src *.nav.no portal-admin.oera.no data: video.qbrick.com play2.qbrick.com analytics.qbrick.com *.ip-only.net blob: widget.uxsignals.com *.psplugin.com *.vimeocdn.com *.hotjar.com *.skyra.no www.vergic.com; object-src video.qbrick.com play2.qbrick.com analytics.qbrick.com *.ip-only.net blob:; connect-src *.nav.no portal-admin.oera.no video.qbrick.com play2.qbrick.com analytics.qbrick.com *.ip-only.net blob: api.uxsignals.com *.skyra.no *.boost.ai *.psplugin.com *.hotjar.com *.hotjar.io *.taskanalytics.com; media-src video.qbrick.com play2.qbrick.com analytics.qbrick.com *.ip-only.net blob: ihb.nav.no; child-src *.nav.no blob:; style-src-elem *.nav.no *.psplugin.com 'unsafe-inline' *.googleapis.com *.gstatic.com; frame-src *.hotjar.com player.vimeo.com video.qbrick.com *.nav.no; frame-ancestors 'self' *.psplugin.com;
Cache-Control s-maxage=86400, stale-while-revalidate
Date Mon, 21 Apr 2025 01:01:00 GMT
App-Name nav-enonicxp-frontend
Via 1.1 google
X-Content-Type-Options nosniff
X-Frame-Options SAMEORIGIN
Vary Accept-Encoding
X-Ua-Compatible IE=Edge
X-Xss-Protection 1; mode=block

About the tool

By using SecurityHeaders.info, you can quickly identify missing or misconfigured headers and take steps to secure your website, improving both security and user confidence.

This tool is widely used by developers, security professionals, and organizations to ensure their websites adhere to best practices in web security.

We also have another analytic tool that is used for identifying popularity metrics, general information about the business, finding similar products and competitors, and much more.

Watch it now at TrustRadar