Server | Apache |
Expires | Thu, 19 Nov 1981 08:52:00 GMT |
Cache-Control | no-store, no-cache, must-revalidate, post-check=0, pre-check=0 |
Pragma | no-cache |
X-Smrtr-Wp-Foundation-Cache | HIT |
X-Frame-Options | SAMEORIGIN |
Access-Control-Allow-Origin | * |
Access-Control-Allow-Methods | POST, GET, PUT, OPTIONS, PATCH, DELETE |
Access-Control-Max-Age | 1000 |
Access-Control-Allow-Headers | X-Requested-With, Content-Type, Origin, Authorization, Accept, Client-Security-Token, Accept-Encoding |
X-XSS-Protection | 1; mode=block |
X-Content-Security-Policy | allow 'self'; |
Content-Security-Policy | default-src 'self'; frame-src www.youtube.com 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' code.angularjs.org www.google-analytics.com ajax.googleapis.com maxcdn.bootstrapcdn.com fonts.googleapis.com www.cambridge.org; style-src 'self' 'unsafe-inline' maxcdn.bootstrapcdn.com fonts.googleapis.com www.cambridge.org cambridge.org; font-src 'self' 'unsafe-inline' data: maxcdn.bootstrapcdn.com fonts.googleapis.com fonts.gstatic.com; img-src 'self' 'unsafe-inline' www.google-analytics.com secure.gravatar.com plugins.svn.wordpress.org data: 0.gravatar.com; connect-src 'self' maps.googleapis.com; object-src 'self'; |
X-Content-Type-Options | nosniff |
Strict-Transport-Security | max-age=31536000; includeSubDomains; preload |
Vary | Accept-Encoding |
Content-Encoding | gzip |
Keep-Alive | timeout=2, max=100 |
Connection | Keep-Alive |
Transfer-Encoding | chunked |
Content-Type | text/html; charset=UTF-8 |