Server | Apache |
Cache-Control | no-cache |
Content-Security-Policy | script-src 'self' 'unsafe-inline' 'unsafe-eval' www.youtube.com *.doubleclick.net www.google-analytics.com ajax.googleapis.com maps.googleapis.com www.googletagmanager.com s7.addthis.com m.addthisedge.com m.addthis.com w.estat.com www.google.com www.gstatic.com;style-src 'self' 'unsafe-inline' code.jquery.com maxcdn.bootstrapcdn.com fonts.googleapis.com www.google.com ajax.googleapis.com; |
X-Content-Security-Policy | script-src 'self' 'unsafe-inline' 'unsafe-eval' www.youtube.com *.doubleclick.net www.google-analytics.com ajax.googleapis.com maps.googleapis.com www.googletagmanager.com s7.addthis.com m.addthisedge.com m.addthis.com w.estat.com www.google.com www.gstatic.com;style-src 'self' 'unsafe-inline' code.jquery.com maxcdn.bootstrapcdn.com fonts.googleapis.com www.google.com ajax.googleapis.com; |
X-Webkit-CSP | script-src 'self' 'unsafe-inline' 'unsafe-eval' www.youtube.com *.doubleclick.net www.google-analytics.com ajax.googleapis.com maps.googleapis.com www.googletagmanager.com s7.addthis.com m.addthisedge.com m.addthis.com w.estat.com www.google.com www.gstatic.com;style-src 'self' 'unsafe-inline' code.jquery.com maxcdn.bootstrapcdn.com fonts.googleapis.com www.google.com ajax.googleapis.com; |
Content-Type | text/html; charset=UTF-8 |
Transfer-Encoding | chunked |
Content-Encoding | gzip |
Strict-Transport-Security | max-age=2592000; includeSubDomains; preload |
Referrer-Policy | no-referrer-when-downgrade |
X-Frame-Options | SAMEORIGIN |
X-XSS-Protection | 1; mode=block |
X-Content-Type-Options | nosniff |