Persistent report
pintelly.com security headers report
Last analyzed:
Available again in 5:00
Score history
2 days · min 67 · max 67 · 0
URL
https://pintelly.com/
Status
200
HTTPS
HTTPS
To-do, by priority
Fails first, then warnings. Tips are things this HTML fetch cannot see.
HSTSErrorNo HSTS
+
No HSTS
Why it matters: Tells browsers to skip HTTP entirely on the next visit.
What to do
Send Strict-Transport-Security with max-age of at least 15552000 (180 days).
Content-Security-PolicyErrorNo CSP
+
No CSP
Why it matters: Limits which scripts, frames and connections the page may use.
What to do
Start with default-src 'self' and add the origins you actually need. Avoid unsafe-inline if you can.
ClickjackingPasssameorigin
+
sameorigin
Why it matters: X-Frame-Options or CSP frame-ancestors stop other sites framing yours.
X-Content-Type-OptionsPassnosniff
+
nosniff
Why it matters: nosniff stops the browser guessing MIME types for scripts and styles.
Referrer-PolicyPasssame-origin
+
same-origin
Why it matters: Controls how much of the URL leaks to the next site.
Permissions-PolicyInfoNot set
+
Not set
Why it matters: Restricts camera, geolocation, and similar APIs. Optional.
Cross-Origin-Opener-PolicyInfoNot set
+
Not set
Why it matters: Isolates the browsing context from window.opener. Optional.
Cross-Origin-Resource-PolicyInfoNot set
+
Not set
Why it matters: Stops other sites embedding this response. Optional.
X-XSS-ProtectionInfo1; mode=block
+
1; mode=block
Why it matters: Deprecated. Modern browsers ignore it; a leftover 1; mode=block can cause issues.
X-Powered-ByPassNot sent
+
Not sent
Why it matters: Advertises the stack to scanners. Not a ranking factor.
ServerInfocloudflare
+
cloudflare
Why it matters: Often a version string. Informational fingerprint.
Security headers sent
- server
- cloudflare
- referrer-policy
- same-origin
- x-frame-options
- SAMEORIGIN
- x-xss-protection
- 1; mode=block
- x-content-type-options
- nosniff
Get this report by email on a schedule, with what changed since last time.

