HTTP Headers: oxygen.com

Security score: 40/100

🛡️ Security Headers
HeaderStatus
Strict-Transport-Security❌ Missing
Content-Security-Policy❌ Missing
X-Content-Type-Options✅ Present
X-Frame-Options✅ Present
X-XSS-Protection❌ Missing
📋 All Response Headers
Accept-Ranges
Access-Control-Allow-Credentials
Access-Control-Allow-Headers
Access-Control-Allow-Methods
Access-Control-Allow-Origin
Cache-Control
Cache-Tags
Connection
Content-Encoding
Content-Language
Content-Length
Content-Type
Date
ETag
Last-Modified
Server
Vary
X-AH-Environment
X-Age
X-Content-Type-Options
X-Drupal-Cache
X-Drupal-Cache-Control
X-Drupal-Dynamic-Cache
X-Frame-Options
X-Generator
X-Ttl
X-UA-Compatible
X-Varnish
X-pubstack