Security header audit of a production site
URL: https://example.comFinal URL: https://example.com/
HTTP 200 OK
Time: 187 ms · Hops: 1
cache-control: max-age=3600, public
content-encoding: gzip
content-security-policy: default-src 'self'; script-src 'self' 'nonce-abc123'
content-type: text/html; charset=utf-8
referrer-policy: strict-origin-when-cross-origin
server: nginx
strict-transport-security: max-age=31536000; includeSubDomains; preload
x-content-type-options: nosniff
x-frame-options: DENY