www.govt.nz | Analytics by SecurityHeaders

HTTP Headers report for www.govt.nz

Header Name Header Data
HTTP status code 200
Strict-Transport-Security max-age=63072000; includeSubDomains
Expires Thu, 17 Apr 2025 14:56:39 GMT
Accept-Ranges bytes
Server nginx
Content-Type text/html; charset=utf-8
Referrer-Policy no-referrer
Cross-Origin-Resource-Policy cross-origin
Last-Modified Mon, 07 Apr 2025 20:02:29 GMT
Vary Accept-Encoding
X-Iinfo 15-25676304-25676321 NNNN CT(226 471 0) RT(1744901799659 108) q(0 1 7 12) r(14 14) U2
Connection keep-alive
X-Frame-Options SAMEORIGIN
X-Cdn Imperva
Content-Security-Policy default-src https://www.govt.nz https://*.cwp.govt.nz https://www.govt.nz/ 'unsafe-eval' 'unsafe-inline' ; base-uri https://www.govt.nz https://*.cwp.govt.nz https://www.govt.nz/ ; frame-ancestors https://www.govt.nz https://*.cwp.govt.nz https://www.govt.nz/ ; style-src 'unsafe-inline' https://www.govt.nz https://*.cwp.govt.nz https://www.govt.nz/ https://api.addressfinder.io https://tagmanager.google.com https://optimize.google.com https://www.google.com https://www.google.co.nz/ads/ga-audiences https://player.vimeo.com https://api.addressfinder.io https://api.addressfinder.io/assets/v3/widget.js ; script-src https://www.govt.nz https://*.cwp.govt.nz https://www.govt.nz/ 'unsafe-eval' 'unsafe-inline' 'unsafe-inline' https://api.addressfinder.io https://www.googletagmanager.com https://fonts.googleapis.com https://*.google-analytics.com https://tagmanager.google.com https://optimize.google.com https://code.jquery.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://staticcdn.co.nz/embed/embed.js 'unsafe-eval' https://player.vimeo.com https://api.addressfinder.io https://api.addressfinder.io/assets/v3/widget.js ; img-src https://www.govt.nz https://*.cwp.govt.nz https://www.govt.nz/ http://www.govt.nz 'self' data: https://*.google-analytics.com https://*.swagger.io https://optimize.google.com https://staticcdn.co.nz/embed/ https://player.vimeo.com https://api.addressfinder.io https://api.addressfinder.io/assets/v3/widget.js ; font-src https://www.govt.nz https://*.cwp.govt.nz https://www.govt.nz/ https://fonts.gstatic.com ; object-src https://www.govt.nz https://*.cwp.govt.nz https://www.govt.nz/ ; frame-src https://www.govt.nz https://*.cwp.govt.nz https://www.govt.nz/ http://www.govt.nz 'self' data: https://*.youtube-nocookie.com https://*.youtube.com https://optimize.google.com https://www.googletagmanager.com/ns.html https://www.google.com/ https://player.vimeo.com https://staticcdn.co.nz/ https://player.vimeo.com https://api.addressfinder.io https://api.addressfinder.io/assets/v3/widget.js ; child-src https://www.govt.nz https://*.cwp.govt.nz https://www.govt.nz/ https://*.youtube-nocookie.com https://*.youtube.com https://optimize.google.com https://www.googletagmanager.com/ns.html ; connect-src https://www.govt.nz https://*.cwp.govt.nz https://www.govt.nz/ https://api.addressfinder.io https://www.google-analytics.com/ https://stats.g.doubleclick.net https://player.vimeo.com https://api.addressfinder.io https://api.addressfinder.io/assets/v3/widget.js ; form-action https://www.govt.nz https://*.cwp.govt.nz https://www.govt.nz/ http://www.govt.nz 'self' ; report-uri ;
Cache-Control no-store, max-age=0
X-Content-Type-Options nosniff
Cross-Origin-Opener-Policy same-origin-allow-popups
Date Thu, 17 Apr 2025 14:56:41 GMT
X-Ua-Compatible IE=edge
Pragma no-cache
Age 0
X-Xss-Protection 1; mode=block
Content-Language en-NZ
X-Varnish 318784182
Set-Cookie SECSESSID=opbtk7k7942iq9atnbgrm287qk; expires=Thu, 17 Apr 2025 15:20:39 GMT; Max-Age=1440; path=/; secure; HttpOnly; SameSite=Strict
Cross-Origin-Embedder-Policy unsafe-none
Permissions-Policy accelerometer=(), camera=(), microphone=(), geolocation=(), usb=(), autoplay=(self "https://player.vimeo.com"), picture-in-picture=(self "https://player.vimeo.com")

About the tool

By using SecurityHeaders.info, you can quickly identify missing or misconfigured headers and take steps to secure your website, improving both security and user confidence.

This tool is widely used by developers, security professionals, and organizations to ensure their websites adhere to best practices in web security.

We also have another analytic tool that is used for identifying popularity metrics, general information about the business, finding similar products and competitors, and much more.

Watch it now at TrustRadar