HTTP Headers: typeform.com

Security score: 60/100

🛡️ Security Headers
HeaderStatus
Strict-Transport-Security✅ Present
Content-Security-Policy❌ Missing
X-Content-Type-Options✅ Present
X-Frame-Options✅ Present
X-XSS-Protection❌ Missing
📋 All Response Headers
Age
Alt-Svc
Cache-Control
Connection
Content-Encoding
Content-Security-Policy-Report-Only
Content-Type
Cross-Origin-Opener-Policy
Date
ETag
Server
Vary
Via
X-Amz-Cf-Id
X-Amz-Cf-Pop
X-Cache
X-Device
X-Experiments
X-Experiments-Raw
X-Language
X-Userid
access-control-allow-headers
access-control-allow-methods
access-control-expose-headers
strict-transport-security
x-envoy-upstream-service-time
x-powered-by
x-promote-business
x-promote-enterprise
x-viewer-country
x-visitor-authenticated
x-visitor-registered