Strict-Transport-Security
Present
max-age=31536000; includeSubDomains; preload
X-Frame-Options
Present
SAMEORIGIN
X-Content-Type-Options
Present
nosniff
X-XSS-Protection
Present
1; mode=block
Content-Security-Policy
Present
default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline';
Referrer-Policy
Present
strict-origin-when-cross-origin
X-Permitted-Cross-Domain-Policies
Present
none
Expect-CT
Present
enforce, max-age=30