HTTP Headers: bbc.com

Security score: 60/100

🛡️ Security Headers
HeaderStatus
Strict-Transport-Security✅ Present
Content-Security-Policy❌ Missing
X-Content-Type-Options✅ Present
X-Frame-Options✅ Present
X-XSS-Protection❌ Missing
📋 All Response Headers
Accept-Ranges
Connection
Content-Length
Content-Type
Date
Fastly-Restarts
Origin-Agent-Cluster
Server
Strict-Transport-Security
Vary
X-BBC-Edge-Cache-Status
X-Cache
X-Cache-Hits
X-Fastly-Cache-Status
X-Fastly-Pre-Flight-Cache
X-Fastly-Pre-Flight-Cache-Status
X-LB-NoCache
X-Robots-Tag
X-Served-By
X-Timer
X-cache-age
alt-svc
belfrage-cache-status
bid
brequestid
bsig
cache-control
content-encoding
etag
nel
referrer-policy
report-to
req-svc-chain
via
x-content-type-options
x-correlation-id
x-envoy-upstream-service-time
x-frame-options