HTTP Headers: worldtimeapi.org

Security score: 40/100

🛡️ Security Headers
HeaderStatus
Strict-Transport-Security❌ Missing
Content-Security-Policy❌ Missing
X-Content-Type-Options✅ Present
X-Frame-Options✅ Present
X-XSS-Protection❌ Missing
📋 All Response Headers
access-control-allow-credentials
access-control-allow-origin
access-control-expose-headers
cache-control
content-length
content-type
cross-origin-window-policy
date
fly-request-id
server
via
x-content-type-options
x-download-options
x-frame-options
x-permitted-cross-domain-policies
x-request-id
x-runtime
x-xss-protection