Server | Apache |
Vary | Accept-Encoding,Cookie,Host |
Strict-Transport-Security | max-age=63072000; includeSubdomains; |
X-Mod-Pagespeed | 1.12.34.2-0 |
X-Frame-Options | SAMEORIGIN |
X-XSS-Protection | 1; mode=block |
X-Content-Type-Options | nosniff |
Referrer-Policy | strict-origin-when-cross-origin |
Content-Security-Policy | default-src 'self' http://hidden.cocopro.de https://www.youtube.com; script-src 'self' http://finanzkaufleute.de https://finanzkaufleute.de http://hidden.cocopro.de 'unsafe-inline' 'unsafe-eval' https://maps.googleapis.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com; img-src * data:; media-src 'self' https://www.youtube.com; font-src 'self' fonts.googleapis.com fonts.gstatic.com https://maxcdn.bootstrapcdn.com https://tr1.cbsistatic.com https://c.disquscdn.com/ data:; object-src 'self' http://messe.vfag.de; child-src 'self' https://www.youtube.com; connect-src 'self' https://messe.vfag.de;upgrade-insecure-requests |
Upgrade-Insecure-Requests | 1 |
Content-Encoding | gzip |
Cache-Control | max-age=3, must-revalidate, max-age=0, no-cache, s-maxage=10 |
Keep-Alive | timeout=5, max=100 |
Connection | Keep-Alive |
Content-Type | text/html; charset=UTF-8 |