openssf.org | Analytics by SecurityHeaders

HTTP Headers report for openssf.org

Header Name Header Data
HTTP status code 200
Access-Control-Allow-Methods GET,POST
Content-Type text/html; charset=UTF-8
Cross-Origin-Embedder-Policy unsafe-none; report-to='default'
Cross-Origin-Embedder-Policy-Report-Only unsafe-none; report-to='default'
Cross-Origin-Opener-Policy unsafe-none
Cross-Origin-Opener-Policy-Report-Only unsafe-none; report-to='default'
Content-Security-Policy default-src 'none'; script-src 'nonce-c9109b7cbe' 'strict-dynamic';script-src-elem 'self' 'nonce-c9109b7cbe' *.hsforms.net *.hs-scripts.com *.googletagmanager.com *.google.com *.osano.com *.hubspot.com *.hsadspixel.net *.hscollectedforms.net *.hsleadflows.net *.hs-banner.com *.facebook.net js.zi-scripts.com ws.zoominfo.com tags.clickagy.com ws-assets.zoominfo.com schedule.zoominfo.com api.schedule.zoominfo.com *.buzzsprout.com snap.licdn.com *.google-analytics.com *.hs-analytics.net *.usemessages.com googleads.g.doubleclick.net js-agent.newrelic.com https://www.googletagmanager.com https://googletagmanager.com https://tagmanager.google.com https://cdnjs.cloudflare.com/ajax/libs/slick-carousel/1.9.0/slick.js;style-src 'unsafe-inline' 'self' *.fontawesome.com fonts.googleapis.com https://googletagmanager.com https://tagmanager.google.com https://fonts.googleapis.com *.osano.com https://cdn.jsdelivr.net/jquery.slick/1.3.15/slick.css; object-src 'self' *.osano.com; base-uri 'self'; connect-src 'self' api-gw.platform.linuxfoundation.org js.zi-scripts.com *.hsforms.com *.hscollectedforms.net analytics.google.com *.google-analytics.com *.hubspot.com *.doubleclick.net *.hubapi.com *.linkedin.com *.osano.com aorta.clickagy.com hemsync.clickagy.com ws.zoominfo.com api.schedule.zoominfo.com *.googleadservices.com www.googletagmanager.com *.google.com js-agent.newrelic.com; font-src 'self' data: *.fontawesome.com fonts.gstatic.com; frame-src 'self' *.osano.com *.hsforms.com *.youtube.com *.google.com *.openssf.org *.landscape2.io *.buzzsprout.com aorta.clickagy.com hemsync.clickagy.com *.doubleclick.net zoom-lfx.platform.linuxfoundation.org; img-src 'self' data: *.buzzsprout.com *.hsforms.com *.hubspot.com *.hubspot.net *.linkedin.com *.ads.linkedin.com secure.gravatar.com *.w.org *.google.com *.google-analytics.com *.facebook.com *.linuxfoundation.org https://googletagmanager.com https://www.googletagmanager.com https://ssl.gstatic.com https://www.gstatic.com https://fonts.gstatic.com *.amazonaws.com;manifest-src 'self'; media-src 'self'; worker-src blob: *.osano.com; frame-ancestors 'self'; form-action 'self' *.hsforms.com;
Cross-Origin-Resource-Policy cross-origin
Referrer-Policy strict-origin-when-cross-origin
X-Permitted-Cross-Domain-Policies none
X-Tec-Api-Root https://openssf.org/wp-json/tribe/events/v1/
X-Cache-Hits 8, 4, 0, 0
Vary Accept-Encoding, Cookie, Cookie
Connection keep-alive
Link <https://openssf.org/wp-json/>; rel="https://api.w.org/"
Permissions-Policy browsing-topics=(), accelerometer=(), autoplay=(), camera=(), cross-origin-isolated=(), display-capture=(self), encrypted-media=(), fullscreen=*, geolocation=(self), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), payment=*, picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(), usb=(), xr-spatial-tracking=(), gamepad=(), serial=()
X-Frame-Options SAMEORIGIN
X-Tec-Api-Version v1
X-Xss-Protection 1; mode=block
Accept-Ranges bytes
X-Served-By cache-chi-kigq8000056-CHI, cache-ams21078-AMS, cache-ams21037-AMS, cache-ams21037-AMS
X-Timer S1744975973.243275,VS0,VE7
X-Content-Type-Options nosniff
X-Pantheon-Styx-Hostname styx-fe3-b-657bb69d44-wwk5d
Age 29440
X-Cache HIT, HIT, MISS, MISS
Access-Control-Allow-Headers Content-Type, Authorization
Access-Control-Allow-Origin *
Cache-Control public, max-age=60, s-maxage=43200, stale-while-revalidate=86400, stale-if-error=604800
X-Content-Security-Policy default-src 'self'; img-src *; media-src * data:;
X-Tec-Api-Origin https://openssf.org
Via 1.1 varnish, 1.1 varnish, 1.1 varnish, 1.1 varnish
Server nginx
Strict-Transport-Security max-age=63072000; includeSubDomains; preload
X-Styx-Req-Id 50ce7c82-1c04-11f0-b6c9-a6e7540df35b
Date Fri, 18 Apr 2025 11:32:53 GMT

About the tool

By using SecurityHeaders.info, you can quickly identify missing or misconfigured headers and take steps to secure your website, improving both security and user confidence.

This tool is widely used by developers, security professionals, and organizations to ensure their websites adhere to best practices in web security.

We also have another analytic tool that is used for identifying popularity metrics, general information about the business, finding similar products and competitors, and much more.

Watch it now at TrustRadar