wcrf.org | Analytics by SecurityHeaders

HTTP Headers report for wcrf.org

Header Name Header Data
HTTP status code 200
X-Edge-Location-Klb 1
Pragma no-cache
Content-Security-Policy connect-src 'self' *.google.com google.com *.google-analytics.com www.google-analytics.com *.analytics.google.com *.cloudflare.com *.doubleclick.net *.hotjar.com *.hotjar.io wss://ws.hotjar.com *.fundraiseup.com *.paypal.com *.fndrsp-checkout.net fndrsp-checkout.net *.fndrsp.net fndrsp.net pagead2.googlesyndication.com *.googlesyndication.com *.civiccomputing.com *.shopifysvc.com *.myshopify.com *.ads.linkedin.com; default-src 'self' www.googletagmanager.com; font-src 'self' data: fonts.gstatic.com *.fundraiseup.com; frame-src 'self' data: *.google.com google.com platform.twitter.com www.googletagmanager.com player.vimeo.com vimeo.com youtube.com www.youtube.com www.youtube-nocookie.com *.twitter.com *.cloudflare.com *.doubleclick.net *.stripe.com *.paypal.com muchloved.com www.muchloved.com *.muchloved.com *.amazonaws.com *.dwcdn.net; img-src 'self' data: www.google-analytics.com www.gstatic.com www.google.co.uk www.googletagmanager.com *.gravatar.com *.vimeocdn.com *.ytimg.com *.twitter.com *.youtube.com *.pixeledeggs.com *.doubleclick.net *.fundraiseup.com ucarecdn.com *.paypal.com *.paypalobjects.com www.facebook.com *.facebook.com cdn.shopify.com *.shopify.com *.ads.linkedin.com *.adalyser.com; media-src 'self' blob: data:; script-src 'self' 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' connect.facebook.net muchloved.com www.muchloved.com *.muchloved.com cc.cdn.civiccomputing.com *.civiccomputing.com *.cdn.civiccomputing.com sdks.shopifycdn.com *.shopifycdn.com snap.licdn.com *.licdn.com *.adalyser.com; script-src-elem 'self' 'unsafe-inline' player.vimeo.com vimeo.com *.google.com www.youtube.com www.youtube-nocookie.com platform.twitter.com googletagmanager.com www.googletagmanager.com www.gstatic.com gstatic.com www.google-analytics.com connect.facebook.net *.cloudflare.com *.hotjar.com *.fundraiseup.com *.stripe.com *.paypal.com *.civiccomputing.com *.cdn.civiccomputing.com cc.cdn.civiccomputing.com muchloved.com www.muchloved.com *.muchloved.com sdks.shopifycdn.com *.shopifycdn.com snap.licdn.com *.licdn.com *.adalyser.com; style-src 'self' 'unsafe-inline' blob: fonts.googleapis.com; style-src-elem 'self' 'unsafe-inline' *.cloudflare.com *.hotjar.com fonts.googleapis.com; worker-src 'self' blob:;
Ki-Cf-Cache-Status HIT
Report-To {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=I4UuGa10M34hnlmuer5qAP12FJN%2BLhGqBFWOJaitzT1VLs5eAnim9YLGASpVTF66VpqrkJfusHJ0YH7fMp5BArFTb4JrcRaOV5J25fFwOyAbHfdyaj89JfkxDoE3QA%3D%3D"}],"group":"cf-nel","max_age":604800}
Connection keep-alive
Expires Thu, 19 Nov 1981 08:52:00 GMT
X-Kinsta-Cache HIT
Age 1525
Cache-Control public, max-age=0, s-maxage=3600
Permissions-Policy geolocation=(),midi=(),sync-xhr=(self),microphone=(),camera=(),magnetometer=(),gyroscope=(),fullscreen=(self),payment=(self "https://pay.google.com" "https://www.gstatic.com")
Referrer-Policy strict-origin
Nel {"success_fraction":0.01,"report_to":"cf-nel","max_age":604800}
Server cloudflare
Content-Type text/html; charset=UTF-8
Cf-Ray 92d1748a3f943379-AMS
Vary Accept-Encoding
Ki-Cache-Type Edge
Alt-Svc h3=":443"; ma=86400
Last-Modified Tue, 08 Apr 2025 11:03:35 GMT
Link <https://www.wcrf.org/wp-json/>; rel="https://api.w.org/", <https://www.wcrf.org/wp-json/wp/v2/pages/14>; rel="alternate"; title="JSON"; type="application/json", <https://www.wcrf.org/>; rel=shortlink
Ki-Edge v=21.0.0;mv=4.0.1
X-Content-Type-Options nosniff
X-Frame-Options SAMEORIGIN
Cf-Cache-Status HIT
Date Tue, 08 Apr 2025 11:34:23 GMT
Ki-Cache-Tag 2ec12dc3-5e9e-41de-97b9-415b5cb0e9d6,2b33dbe34c79666711d5b4fb36e72daf0d7d96627e2c21e79ea629a47c07bf62

About the tool

By using SecurityHeaders.info, you can quickly identify missing or misconfigured headers and take steps to secure your website, improving both security and user confidence.

This tool is widely used by developers, security professionals, and organizations to ensure their websites adhere to best practices in web security.

We also have another analytic tool that is used for identifying popularity metrics, general information about the business, finding similar products and competitors, and much more.

Watch it now at TrustRadar