nparks.gov.sg | Analytics by SecurityHeaders

HTTP Headers report for nparks.gov.sg

Header Name Header Data
HTTP status code 200
X-Aspnet-Version 4.0.30319
Cross-Origin-Embedder-Policy unsafe-none
Cross-Origin-Opener-Policy unsafe-none
Permissions-Policy accelerometer=(self), ambient-light-sensor=(self), autoplay=(self), battery=(self), camera=(self), cross-origin-isolated=(self), display-capture=(self), document-domain=(self), encrypted-media=(self), execution-while-not-rendered=(self), execution-while-out-of-viewport=(self), fullscreen=(self), geolocation=(self), gyroscope=(self), keyboard-map=(self), magnetometer=(self), microphone=(self), midi=(self), navigation-override=(self), payment=(self), picture-in-picture=(self), publickey-credentials-get=(self), screen-wake-lock=(self), sync-xhr=(self), usb=(self), web-share=(self), xr-spatial-tracking=(self)
Connection keep-alive
Cache-Control no-cache
Pragma no-cache
Expires -1
Referrer-Policy no-referrer-when-downgrade
Strict-Transport-Security max-age=31536000; includeSubDomains
X-Frame-Options SAMEORIGIN
X-Amz-Cf-Id CePdVsvha12tw9_oVCXm4JiihHlAVh66BrpmA1Bs4V3YgcrujiJsag==
Vary Origin
Content-Type text/html; charset=utf-8
X-Xss-Protection 1; mode=block
X-Content-Type-Options nosniff
X-Amz-Cf-Pop AMS58-P6
Date Wed, 16 Apr 2025 06:01:33 GMT
Content-Security-Policy default-src 'self' https://www.search.gov.sg https://*.dcube.cloud/ https://www.onemap.gov.sg/ https://www.stg.search.gov.sg/ https://*.wogaa.sg https://*.vica.gov.sg; script-src 'self' *.googleapis.com *.gstatic.com www.google.com apis.google.com connect.facebook.net ajax.aspnetcdn.com https://www.youtube.com platform.twitter.com https://syndication.twitter.com/ https://s.ytimg.com https://publish.twitter.com *.twimg.com platform.linkedin.com http://platform.stumbleupon.com/1/widgets.js https://*.googletagmanager.com 'nonce-c59fa6b3458b4bf684eb2b025552a833' 'unsafe-eval' blob: https://api.search.gov.sg https://www.search.gov.sg https://*.dcube.cloud https://stg.api.search.gov.sg https://www.stg.search.gov.sg https://www.onemap.gov.sg https://*.wogaa.sg https://*.hotjar.com https://*.vica.gov.sg https://cdn.insight.sitefinity.com https://dec.azureedge.net cdn.ampproject.org web-chat.nativechat.com; style-src 'self' *.googleapis.com *.gstatic.com netdna.bootstrapcdn.com kendo.cdn.telerik.com www.google.com platform.twitter.com/css/ *.twimg.com 'unsafe-inline' https://www.search.gov.sg https://assets.dcube.cloud/ https://www.stg.search.gov.sg https://www.onemap.gov.sg https://assets.wogaa.sg/ https://*.hotjar.com https://*.vica.gov.sg https://cdn.insight.sitefinity.com https://dec.azureedge.net web-chat.nativechat.com; img-src 'self' *.gstatic.com *.googleapis.com platform.tumblr.com web.facebook.com www.facebook.com www.redditstatic.com www.linkedin.com i.ytimg.com https://syndication.twitter.com https://static.licdn.com/scds/common/u/images/apps/connect/sprites/sprite_connect_v14.png pbs.twimg.com platform.twitter.com/css/ *.twimg.com data: blob: https://*.googletagmanager.com https://assets.search.gov.sg https://www.onemap.gov.sg/maps/tiles/Default/ https://*.cdninstagram.com https://*.google-analytics.com https://*.analytics.google.com https://*.g.doubleclick.net https://*.google.com https://www.onemap.gov.sg/ https://*.hotjar.com https://*.vica.gov.sg https://www.volunteer.gov.sg https://cdn.insight.sitefinity.com https://dec.azureedge.net web-chat.nativechat.com; font-src 'self' fonts.gstatic.com kendo.cdn.telerik.com netdna.bootstrapcdn.com data: https://www.search.gov.sg https://assets.dcube.cloud/fonts/ https://www.stg.search.gov.sg https://assets.wogaa.sg/fonts/ https://*.hotjar.com; frame-src 'self' https://www.google.com https://www.search.gov.sg https://www.youtube.com https://www.stg.search.gov.sg https://www.onemap.gov.sg https://www.facebook.com web-chat.nativechat.com; connect-src 'self' data: accounts.google.com *.gstatic.com https://*.googletagmanager.com https://api.search.gov.sg https://assets.search.gov.sg https://*.dcube.cloud https://*.google-analytics.com https://*.analytics.google.com https://*.g.doubleclick.net https://*.google.com https://stg.api.search.gov.sg https://*.wogaa.sg https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com https://*.vica.gov.sg wss://chat.vica.gov.sg https://*.insight.sitefinity.com https://*.dec.sitefinity.com; media-src 'self' data: blob:; child-src 'self' https://platform.twitter.com/ https://syndication.twitter.com/ https://www.youtube.com/ https://www.youtube-nocookie.com https://player.vimeo.com/ https://w.soundcloud.com/ apis.google.com accounts.google.com staticxx.facebook.com www.facebook.com web.facebook.com badge.stumbleupon.com web-chat.nativechat.com; frame-ancestors https://www.onemap.gov.sg 'self'
X-Cache Hit from cloudfront
Cross-Origin-Resource-Policy cross-origin
Via 1.1 2e6275c73445d58429e5205e011d70ba.cloudfront.net (CloudFront)
Age 242203

About the tool

By using SecurityHeaders.info, you can quickly identify missing or misconfigured headers and take steps to secure your website, improving both security and user confidence.

This tool is widely used by developers, security professionals, and organizations to ensure their websites adhere to best practices in web security.

We also have another analytic tool that is used for identifying popularity metrics, general information about the business, finding similar products and competitors, and much more.

Watch it now at TrustRadar