owasp.org | Analytics by SecurityHeaders

HTTP Headers report for owasp.org

Header Name Header Data
HTTP status code 200
Last-Modified Mon, 07 Apr 2025 04:16:47 GMT
Content-Security-Policy default-src 'self' https://*.fontawesome.com https://api.github.com https://*.githubusercontent.com https://*.google-analytics.com https://owaspadmin.azurewebsites.net https://*.twimg.com https://platform.twitter.com https://www.youtube.com https://*.doubleclick.net; frame-ancestors 'self'; frame-src https://*.vuejs.org https://*.stripe.com https://*.wufoo.com https://*.sched.com https://*.google.com https://*.twitter.com https://www.youtube.com https://w.soundcloud.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://viewer.diagrams.net https://fonts.googleapis.com https://*.fontawesome.com https://app.diagrams.net https://cdnjs.cloudflare.com https://cse.google.com https://*.vuejs.org https://*.stripe.com https://*.wufoo.com https://*.youtube.com https://*.meetup.com https://*.sched.com https://*.google-analytics.com https://unpkg.com https://buttons.github.io https://www.google.com https://*.gstatic.com https://*.twitter.com https://*.twimg.com; style-src 'self' 'unsafe-inline' https://*.gstatic.com https://cdnjs.cloudflare.com https://www.google.com https://fonts.googleapis.com https://platform.twitter.com https://*.twimg.com data:; font-src 'self' https://*.fontawesome.com fonts.gstatic.com; manifest-src 'self' https://pay.google.com; img-src 'self' https://*.globalappsec.org https://render.com https://*.render.com https://okteto.com https://*.okteto.com data: www.w3.org https://*.bestpractices.dev https://licensebuttons.net https://img.shields.io https://*.twitter.com https://github.githubassets.com https://*.twimg.com https://platform.twitter.com https://*.githubusercontent.com https://*.vercel.app https://*.cloudfront.net https://*.coreinfrastructure.org https://*.securityknowledgeframework.org https://badges.gitter.im https://travis-ci.org https://api.travis-ci.org https://s3.amazonaws.com https://snyk.io https://coveralls.io https://requires.io https://github.com https://*.googleapis.com https://*.google.com https://*.gstatic.com
X-Cache HIT
X-Cache-Hits 0
Access-Control-Allow-Origin *
Via 1.1 varnish
X-Fastly-Request-Id bf5d58e0974f83029151a2cd73be6c51590e7a98
Date Mon, 07 Apr 2025 08:13:30 GMT
Content-Type text/html; charset=utf-8
Referrer-Policy same-origin
X-Timer S1744013610.059405,VS0,VE110
Cf-Ray 92c810e6ad8c5c47-AMS
Age 0
Expires Mon, 07 Apr 2025 06:06:53 GMT
X-Proxy-Cache MISS
Vary Accept-Encoding
Permissions-Policy geolocation=(self)
X-Content-Type-Options nosniff
X-Frame-Options SAMEORIGIN
Connection keep-alive
Cf-Cache-Status DYNAMIC
Strict-Transport-Security max-age=31536000; includeSubDomains
X-Served-By cache-rtm-ehrd2290028-RTM
Server cloudflare
Cache-Control max-age=600
X-Github-Request-Id 8AAC:17115E:6657B24:67433F1:67F36925

About the tool

By using SecurityHeaders.info, you can quickly identify missing or misconfigured headers and take steps to secure your website, improving both security and user confidence.

This tool is widely used by developers, security professionals, and organizations to ensure their websites adhere to best practices in web security.

We also have another analytic tool that is used for identifying popularity metrics, general information about the business, finding similar products and competitors, and much more.

Watch it now at TrustRadar