Technical Information
| HTTP Status Code | 200 |
| HTTP Version | HTTP/1.1 |
| HTTPS | ✔ Available |
| IP Address | 188.165.37.84 |
| Compression | gzip |
|
🔒 🟡 Mixed Content (2 HTTP resources) | The page is served over HTTPS but loads 2 resource(s) over HTTP. This may be blocked in modern browsers. |
|
ℹ 🔵 Missing X-Frame-Options | The site can be embedded in iframes by third parties (clickjacking risk). |
HTTP Status Code 200
HTTP Version HTTP/1.1
HTTPS ✔ Available
IP Address 188.165.37.84
Compression gzip
🔒 🟡 Mixed Content (2 HTTP resources) The page is served over HTTPS but loads 2 resource(s) over HTTP. This may be blocked in modern browsers.
ℹ 🔵 Missing X-Frame-Options The site can be embedded in iframes by third parties (clickjacking risk).
Redirect Chain
| # | URL | HTTP Status Code | Status |
| 1 | https://orsac.fr:443 | 301 | HTTP/2 301 |
| 2 | https://www.orsac.fr/ | 200 | HTTP/2 200 |
#1 URL https://orsac.fr:443
HTTP Status Code 301
Status HTTP/2 301
#2 URL https://www.orsac.fr/
HTTP Status Code 200
Status HTTP/2 200
Performance
| DNS Lookup | 37.9 ms |
| TCP Connect | 43.3 ms |
| TLS Handshake | 9.8 ms |
| Time To First Byte (TTFB) | 341.7 ms |
| Content Download | 20.1 ms |
| Total Response Time | 361.9 ms |
DNS Lookup 37.9 ms
TCP Connect 43.3 ms
TLS Handshake 9.8 ms
Time To First Byte (TTFB) 341.7 ms
Content Download 20.1 ms
Total Response Time 361.9 ms
Security
| HTTPS | ✔ Enabled |
| HSTS | ✔ max-age=31536000; includeSubdomains; preload |
| CSP | ✔ Configured |
| X-Frame-Options | ⚠ Not configured |
| X-Content-Type-Options | ✔ nosniff |
| Referrer Policy | unsafe-url |
| Permissions Policy | ✔ Configured |
| HTTP/2 | ⚠ HTTP/1.1 |
HTTPS ✔ Enabled
HSTS ✔ max-age=31536000; includeSubdomains; preload
CSP ✔ Configured
X-Frame-Options ⚠ Not configured
X-Content-Type-Options ✔ nosniff
Referrer Policy unsafe-url
Permissions Policy ✔ Configured
HTTP/2 ⚠ HTTP/1.1
SEO Quick Check
| Title | Orsac |
| Canonical | https://www.orsac.fr/ |
| Robots Meta | max-image-preview:large |
| Open Graph Title | Page d’accueil |
| Twitter Title | Page d’accueil |
Title Orsac
Canonical https://www.orsac.fr/
Robots Meta max-image-preview:large
Open Graph Title Page d’accueil
Twitter Title Page d’accueil
Detected Technologies
| Technology | WordPress jQuery Google Analytics Cloudflare PHP |
Technology WordPress jQuery Google Analytics Cloudflare PHP
HTTP Headers
| Date
| Thu, 23 Jul 2026 12:23:37 GMT |
| Content-type
| text/html; charset=UTF-8 |
| Vary
| Accept-Encoding, Cookie |
| Link
| ; rel="https://api.w.org/", ; rel="alternate"; title="JSON"; type="application/json", ; rel=shortlink |
| Strict-transport-security
| max-age=31536000; includeSubdomains; preload |
| X-content-type-options
| nosniff |
| Referrer-policy
| unsafe-url |
| X-xss-protection
| 1; mode=block |
| Content-security-policy
| default-src * 'unsafe-inline' 'unsafe-eval'; frame-ancestors 'self' https://*; object-src 'self' data: blob: https://*; font-src * data:; script-src * 'unsafe-inline' 'unsafe-eval' blob: data:; connect-src * 'unsafe-inline'; img-src * data: blob: 'unsafe-inline' 'self' https:; frame-src 'self' https: blob: data:; style-src * 'unsafe-inline'; |
| Permissions-policy
| autoplay=*, geolocation=(self), fullscreen=* |
| Content-encoding
| gzip |
Meta Tags
| Robots | max-image-preview:large |
| Viewport | width=device-width, initial-scale=1.0, minimum-scale=1.0 |
| X-UA-Compatible | ie=edge |
| Canonical | https://www.orsac.fr/ |
| Generator | WordPress 6.9 |
| Msapplication-TileImage |  |
Date Thu, 23 Jul 2026 12:23:37 GMT
Content-type text/html; charset=UTF-8
Vary Accept-Encoding, Cookie
Link ; rel="https://api.w.org/", ; rel="alternate"; title="JSON"; type="application/json", ; rel=shortlink
Strict-transport-security max-age=31536000; includeSubdomains; preload
X-content-type-options nosniff
Referrer-policy unsafe-url
X-xss-protection 1; mode=block
Content-security-policy default-src * 'unsafe-inline' 'unsafe-eval'; frame-ancestors 'self' https://*; object-src 'self' data: blob: https://*; font-src * data:; script-src * 'unsafe-inline' 'unsafe-eval' blob: data:; connect-src * 'unsafe-inline'; img-src * data: blob: 'unsafe-inline' 'self' https:; frame-src 'self' https: blob: data:; style-src * 'unsafe-inline';
Permissions-policy autoplay=*, geolocation=(self), fullscreen=*
Content-encoding gzip