Technical Information
| HTTP Status Code | 200 |
| HTTP Version | HTTP/1.1 |
| HTTPS | ✔ Available |
| IP Address | 138.201.49.62 |
| Server Software | nginx/1.19.2 |
| Compression | gzip |
|
ℹ 🔵 Missing Content Security Policy | CSP is not configured. It helps prevent XSS attacks and content injection. |
HTTP Status Code 200
HTTP Version HTTP/1.1
HTTPS ✔ Available
IP Address 138.201.49.62
Server Software nginx/1.19.2
Compression gzip
ℹ 🔵 Missing Content Security Policy CSP is not configured. It helps prevent XSS attacks and content injection.
Performance
| DNS Lookup | 17.9 ms |
| TCP Connect | 31.7 ms |
| TLS Handshake | 26 ms |
| Time To First Byte (TTFB) | 100.3 ms |
| Content Download | 13.6 ms |
| Total Response Time | 114 ms |
DNS Lookup 17.9 ms
TCP Connect 31.7 ms
TLS Handshake 26 ms
Time To First Byte (TTFB) 100.3 ms
Content Download 13.6 ms
Total Response Time 114 ms
Security
| HTTPS | ✔ Enabled |
| HSTS | ✔ max-age=15724800; includeSubDomains |
| CSP | ⚠ Not configured |
| X-Frame-Options | ✔ SAMEORIGIN |
| X-Content-Type-Options | ✔ nosniff |
| Referrer Policy | strict-origin-when-cross-origin |
| HTTP/2 | ⚠ HTTP/1.1 |
HTTPS ✔ Enabled
HSTS ✔ max-age=15724800; includeSubDomains
CSP ⚠ Not configured
X-Frame-Options ✔ SAMEORIGIN
X-Content-Type-Options ✔ nosniff
Referrer Policy strict-origin-when-cross-origin
HTTP/2 ⚠ HTTP/1.1
SEO Quick Check
Title Palai (beta)
Detected Technologies
| Technology | Google Analytics Nginx |
Technology Google Analytics Nginx
HTTP Headers
| Server
| nginx/1.19.2 |
| Date
| Thu, 23 Jul 2026 09:42:27 GMT |
| Content-type
| text/html; charset=utf-8 |
| Vary
| Accept-Language |
| X-frame-options
| SAMEORIGIN |
| X-xss-protection
| 1; mode=block |
| X-content-type-options
| nosniff |
| X-download-options
| noopen |
| X-permitted-cross-domain-policies
| none |
| Referrer-policy
| strict-origin-when-cross-origin |
| Link
| ; rel=preload; as=style; nopush,; rel=preload; as=script; nopush |
| Etag
| W/"8ba607ff2d4b7e674d6773023b53bba8" |
| Cache-control
| max-age=0, private, must-revalidate |
| Set-cookie
| _palai_community_site_session=4Wcpv0tZ68rDi1U5jmanDQKXnmC5P35NPFvDVLuCG3pOGEg%2Fs3WnCCrp5h2453LNimS7jl0xyUsNNp%2FkmPvoyHFgD2imtL5ARbGWoVh8XaFJ9GroPCAeK56tcwUy8TBWB6IhhIcCJTIvLqlR7x9hyOVCJ0m9I8KZPkeqlRVurNX%2Fu5Pk71%2BPHr23JhOcOmrBoVnA4pw5PGFZydh4CejTcw18fVi6FayoF8SF56QsxXe%2BIAYtJ5WA6eK9MW6We6mXDwFGEzaB7SCfiastZr9dvbT9SiLVvFWjHoR6qmQxvHSRtFn7Bg%3D%3D--s%2FTfVOF5vKU3lfSU--DH65RCAwYWMFHd9AgEsemg%3D%3D; path=/; HttpOnly; SameSite=Lax |
| X-request-id
| 45b9234b59b216fafeaba9f910a719a6 |
| X-runtime
| 0.017241 |
| Strict-transport-security
| max-age=15724800; includeSubDomains |
| Content-encoding
| gzip |
Meta Tags
| Csrf-param | authenticity_token |
| Csrf-token | PmpArO8mB3T_2WTi0doNNOTJwOV73Kp8a-ipD_sJQWEwWWJ9KsbIJV-jVjod-jvHkWyXyGmuhzxIzBeZxI19og |
Server nginx/1.19.2
Date Thu, 23 Jul 2026 09:42:27 GMT
Content-type text/html; charset=utf-8
Vary Accept-Language
X-frame-options SAMEORIGIN
X-xss-protection 1; mode=block
X-content-type-options nosniff
X-download-options noopen
X-permitted-cross-domain-policies none
Referrer-policy strict-origin-when-cross-origin
Link ; rel=preload; as=style; nopush,; rel=preload; as=script; nopush
Etag W/"8ba607ff2d4b7e674d6773023b53bba8"
Cache-control max-age=0, private, must-revalidate
Set-cookie _palai_community_site_session=4Wcpv0tZ68rDi1U5jmanDQKXnmC5P35NPFvDVLuCG3pOGEg%2Fs3WnCCrp5h2453LNimS7jl0xyUsNNp%2FkmPvoyHFgD2imtL5ARbGWoVh8XaFJ9GroPCAeK56tcwUy8TBWB6IhhIcCJTIvLqlR7x9hyOVCJ0m9I8KZPkeqlRVurNX%2Fu5Pk71%2BPHr23JhOcOmrBoVnA4pw5PGFZydh4CejTcw18fVi6FayoF8SF56QsxXe%2BIAYtJ5WA6eK9MW6We6mXDwFGEzaB7SCfiastZr9dvbT9SiLVvFWjHoR6qmQxvHSRtFn7Bg%3D%3D--s%2FTfVOF5vKU3lfSU--DH65RCAwYWMFHd9AgEsemg%3D%3D; path=/; HttpOnly; SameSite=Lax
X-request-id 45b9234b59b216fafeaba9f910a719a6
X-runtime 0.017241
Strict-transport-security max-age=15724800; includeSubDomains
Content-encoding gzip