waves.tech | Analytics by SecurityHeaders

HTTP Headers report for waves.tech

Header Name Header Data
HTTP status code 200
Content-Type text/html; charset=utf-8
Server cloudflare
Cf-Ray 92d186458b7a660e-AMS
Cf-Cache-Status DYNAMIC
Server-Timing cfL4;desc="?proto=TCP&rtt=781&min_rtt=754&rtt_var=239&sent=5&recv=8&lost=0&retrans=0&sent_bytes=4183&recv_bytes=1809&delivery_rate=5153024&cwnd=217&unsent_bytes=0&cid=65cc14c117cc7ad2&ts=158&x=0"
Cross-Origin-Opener-Policy same-origin
Expect-Ct max-age=0
Access-Control-Allow-Headers DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization
Referrer-Policy origin
Access-Control-Max-Age 1728000
Alt-Svc h3=":443"; ma=86400
X-Frame-Options SAMEORIGIN
Origin-Agent-Cluster ?1
X-Permitted-Cross-Domain-Policies none
Report-To {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=GM7rGboDU1eCtNa8uUtnZFRcpuHHcM8jzNEsqXMpojvxMJYnps0JpYnJ5gL6T2pl6Hf%2FemRID%2B%2BqCy1ZYsdxqNDIGr%2F0ih0t1dsXx01ki5u6%2FuCQ0XIiOki5RYks"}],"group":"cf-nel","max_age":604800}
X-Dns-Prefetch-Control off
X-Content-Type-Options nosniff
Access-Control-Allow-Methods PUT, GET, POST, OPTIONS
Access-Control-Allow-Credentials true
Strict-Transport-Security max-age=15552000; includeSubDomains
X-Download-Options noopen
Access-Control-Allow-Origin *
Date Tue, 08 Apr 2025 11:46:29 GMT
Connection keep-alive
Nel {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Content-Security-Policy default-src 'self' https://waves.exchange https://testnet.waves.exchange https://nodes-testnet.wavesnodes.com https://nodes.wavesnodes.com;img-src 'self' data: https:;font-src 'self' data: https://fonts.gstatic.com https://fonts.googleapis.com;style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://fonts.gstatic.com;script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://www.google-analytics.com;script-src-attr 'self' 'unsafe-inline';base-uri 'self';block-all-mixed-content;form-action 'self';frame-ancestors 'self';object-src 'none';upgrade-insecure-requests
Cross-Origin-Resource-Policy same-origin
X-Xss-Protection 0
Set-Cookie route=1744112671.904.1522.812386|6cd405259aa09c8c629bb4cc9362c35f; Expires=Tue, 08-Apr-25 11:54:30 GMT; Max-Age=600; Path=/; Secure; HttpOnly
Vary Accept-Encoding

About the tool

By using SecurityHeaders.info, you can quickly identify missing or misconfigured headers and take steps to secure your website, improving both security and user confidence.

This tool is widely used by developers, security professionals, and organizations to ensure their websites adhere to best practices in web security.

We also have another analytic tool that is used for identifying popularity metrics, general information about the business, finding similar products and competitors, and much more.

Watch it now at TrustRadar