HTTP Headers: dracoon.cloud

Security score: 40/100

🛡️ Security Headers
HeaderStatus
Strict-Transport-Security❌ Missing
Content-Security-Policy❌ Missing
X-Content-Type-Options✅ Present
X-Frame-Options✅ Present
X-XSS-Protection❌ Missing
📋 All Response Headers
CF-Cache-Status
CF-Ray
Cache-Control
Connection
Content-Encoding
Content-Type
Date
Last-Modified
Link
NEL
Report-To
Server
Strict-Transport-Security
Vary
access-control-allow-credentials
alt-svc
cache-tag
content-security-policy
edge-cache-tag
referrer-policy
x-content-type-options
x-envoy-upstream-service-time
x-evy-trace-listener
x-evy-trace-route-configuration
x-evy-trace-route-service-name
x-evy-trace-served-by-pod
x-evy-trace-virtual-host
x-hs-cache-config
x-hs-cfworker-meta
x-hs-content-id
x-hs-hub-id
x-hubspot-correlation-id
x-request-id