Header Name | Header Data |
---|---|
HTTP status code | 200 |
Content-Type | text/html; charset=utf-8 |
X-Content-Type-Options | nosniff |
Expires | 0 |
Content-Security-Policy | connect-src 'self' mixpanel-api-proxy-soaps.ondigitalocean.app https://uploads.intercomcdn.com *.stripe.com connect.facebook.net fbcapi.novoresume.io novoresume.com *.pinterest.com api.usabilla.com api-iam.intercom.io wss://nexus-websocket-a.intercom.io *.google.com vc.hotjar.io *.hotjar.com ws://*.hotjar.com *.doubleclick.net *.clarity.ms *.linkedin.com cdn.linkedin.oribi.io https://widget.trustpilot.com https://vimeo.com *.novoresume.com; default-src 'self' 'unsafe-inline' *.novoresume.com; font-src 'self' data: fonts.gstatic.com *.novoresume.com *.googleapis.com d6tizftlrpuof.cloudfront.net js.intercomcdn.com *.novoresume.com; frame-src 'self' *.stripe.com *.googleapis.com *.pinterest.com d6tizftlrpuof.cloudfront.net *.google.com *.hotjar.com *.novoresume.com https://intercom-sheets.com https://optimize.google.com https://widget.trustpilot.com https://player.vimeo.com *.novoresume.com; img-src 'self' data: *.novoresume.com https://downloads.intercomcdn.com https://www.googletagmanager.com https://cx.atdmt.com *.clarity.ms *.bing.com csi.gstatic.com www.gstatic.com *.doubleclick.net log.pinterest.com *.google.com connect.facebook.net fbcapi.novoresume.io *.pinterest.com *.googleadservices.com www.facebook.com d6tizftlrpuof.cloudfront.net w.usabilla.com gifs.intercomcdn.com t.co static.intercomassets.com js.intercomcdn.com https://optimize.google.com https://bat.bing.com *.linkedin.com https://*.vimeocdn.com *.novoresume.com www.google.nl; media-src 'self' js.intercomcdn.com *.novoresume.com *.novoresume.com; object-src 'self' 'unsafe-eval' *.novoresume.com *.novoresume.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.trustpilot.com *.stripe.com *.novoresume.com mixpanel-api-proxy-soaps.ondigitalocean.app d6tizftlrpuof.cloudfront.net *.clarity.ms *.google.com *.googleadservices.com connect.facebook.net fbcapi.novoresume.io *.pinimg.com snap.licdn.com *.pinterest.com www.googletagmanager.com *.doubleclick.net www.facebook.com api.usabilla.com w.usabilla.com widget.intercom.io js.intercomcdn.com *.hotjar.com https://optimize.google.com https://bat.bing.com https://cdn.jsdelivr.net/npm/lodash.throttle@4.1.1/index.min.js https://cdn.jsdelivr.net/npm/lodash@4.17.21/lodash.min.js https://widget.trustpilot.com https://player.vimeo.com *.novoresume.com www.google.nl; style-src 'self' 'unsafe-inline' *.novoresume.com tagmanager.google.com d6tizftlrpuof.cloudfront.net *.googleapis.com https://optimize.google.com *.novoresume.com |
Date | Sat, 19 Apr 2025 00:04:13 GMT |
X-Frame-Options | Sameorigin |
X-Xss-Protection | 1; mode=block |
Connection | keep-alive |
Cache-Control | no-store, no-cache, must-revalidate, proxy-revalidate |
Pragma | no-cache |
Strict-Transport-Security | max-age=15768000; includeSubDomains |
Surrogate-Control | no-store |
Vary | Accept-Encoding |
By using SecurityHeaders.info, you can quickly identify missing or misconfigured headers and take steps to secure your website, improving both security and user confidence.
This tool is widely used by developers, security professionals, and organizations to ensure their websites adhere to best practices in web security.
We also have another analytic tool that is used for identifying popularity metrics, general information about the business, finding similar products and competitors, and much more.
Watch it now at TrustRadar