Technical Information
| HTTP Status Code | 200 |
| HTTP Version | HTTP/1.1 |
| HTTPS | ✔ Available |
| IP Address | 199.116.164.229 |
| Server Software | Apache |
| Compression | gzip |
|
ℹ 🔵 Missing Content Security Policy | CSP is not configured. It helps prevent XSS attacks and content injection. |
|
ℹ 🔵 Missing X-Frame-Options | The site can be embedded in iframes by third parties (clickjacking risk). |
HTTP Status Code 200
HTTP Version HTTP/1.1
HTTPS ✔ Available
IP Address 199.116.164.229
Server Software Apache
Compression gzip
ℹ 🔵 Missing Content Security Policy CSP is not configured. It helps prevent XSS attacks and content injection.
ℹ 🔵 Missing X-Frame-Options The site can be embedded in iframes by third parties (clickjacking risk).
Redirect Chain
| # | URL | HTTP Status Code | Status |
| 1 | https://pandora.com:443 | 301 | HTTP/2 301 |
| 2 | https://www.pandora.com | 302 | HTTP/2 302 |
| 3 | https://www.pandora.com/restricted | 200 | HTTP/2 200 |
#1 URL https://pandora.com:443
HTTP Status Code 301
Status HTTP/2 301
#2 URL https://www.pandora.com
HTTP Status Code 302
Status HTTP/2 302
#3 URL https://www.pandora.com/restricted
HTTP Status Code 200
Status HTTP/2 200
Performance
| DNS Lookup | 4.1 ms |
| TCP Connect | 83.5 ms |
| TLS Handshake | 161.8 ms |
| Time To First Byte (TTFB) | 330.7 ms |
| Content Download | 0.2 ms |
| Total Response Time | 330.9 ms |
DNS Lookup 4.1 ms
TCP Connect 83.5 ms
TLS Handshake 161.8 ms
Time To First Byte (TTFB) 330.7 ms
Content Download 0.2 ms
Total Response Time 330.9 ms
Security
| HTTPS | ✔ Enabled |
| HSTS | ✔ max-age=31536000 |
| CSP | ⚠ Not configured |
| X-Frame-Options | ⚠ Not configured |
| X-Content-Type-Options | ⚠ Not configured |
| HTTP/2 | ⚠ HTTP/1.1 |
HTTPS ✔ Enabled
HSTS ✔ max-age=31536000
CSP ⚠ Not configured
X-Frame-Options ⚠ Not configured
X-Content-Type-Options ⚠ Not configured
HTTP/2 ⚠ HTTP/1.1
SEO Quick Check
Title Pandora
Detected Technologies
| Technology | jQuery Google Analytics Google Tag Manager Apache |
Technology jQuery Google Analytics Google Tag Manager Apache
HTTP Headers
| Date
| Fri, 24 Jul 2026 11:12:23 GMT |
| Server
| Apache |
| Content-type
| text/html;charset=utf-8 |
| Expires
| Thu, 01 Jan 1970 00:00:00 GMT |
| Vary
| Accept-Encoding,User-Agent |
| Set-cookie
| v2regbstage=;Path=/;Domain=.pandora.com;Expires=Thu, 01-Jan-1970 00:00:00 GMT;Max-Age=0 |
| Content-encoding
| gzip |
| Content-security-policy-report-only
| script-src 'self' 'unsafe-inline' 'unsafe-eval' 'report-sample' https://*.savagebeast.com https://pandora.com https://*.pandora.com https://staging.cdn-net.com https://cdn.cookielaw.org https://assets.adobedtm.com https://*.adsafeprotected.com https://ep2.adtrafficquality.google https://fundingchoicesmessages.google.com https://*.googlesyndication.com https://*.google-analytics.com https://www.googletagmanager.com https://www.googletagservices.com https://imasdk.googleapis.com https://storage.googleapis.com https://*.doubleclick.net https://*.doubleverify.com https://pagead2.googlesyndication.com https://s0.2mdn.net https://cdn.branch.io https://app.link https://client.px-cloud.net https://connect.facebook.net https://sb.scorecardresearch.com https://secure-us.imrworldwide.com https://z.moatads.com https://lex.33across.com https://s.adroll.com https://d.adroll.com https://*.adswizz.com https://ads.revjet.com https://pix.revjet.com https://seal.verisign.com https://code.jquery.com https://snap.licdn.com; report-uri https://browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub16b313e1658347a16504b662a893cd7e&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=env%3Aproduction; report-to csp-endpoint; |
| Reporting-endpoints
| csp-endpoint="https://browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub16b313e1658347a16504b662a893cd7e&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=env%3Aproduction" |
| Content-length
| 9472 |
| Strict-transport-security
| max-age=31536000 |
Date Fri, 24 Jul 2026 11:12:23 GMT
Server Apache
Content-type text/html;charset=utf-8
Expires Thu, 01 Jan 1970 00:00:00 GMT
Vary Accept-Encoding,User-Agent
Set-cookie v2regbstage=;Path=/;Domain=.pandora.com;Expires=Thu, 01-Jan-1970 00:00:00 GMT;Max-Age=0
Content-encoding gzip
Content-security-policy-report-only script-src 'self' 'unsafe-inline' 'unsafe-eval' 'report-sample' https://*.savagebeast.com https://pandora.com https://*.pandora.com https://staging.cdn-net.com https://cdn.cookielaw.org https://assets.adobedtm.com https://*.adsafeprotected.com https://ep2.adtrafficquality.google https://fundingchoicesmessages.google.com https://*.googlesyndication.com https://*.google-analytics.com https://www.googletagmanager.com https://www.googletagservices.com https://imasdk.googleapis.com https://storage.googleapis.com https://*.doubleclick.net https://*.doubleverify.com https://pagead2.googlesyndication.com https://s0.2mdn.net https://cdn.branch.io https://app.link https://client.px-cloud.net https://connect.facebook.net https://sb.scorecardresearch.com https://secure-us.imrworldwide.com https://z.moatads.com https://lex.33across.com https://s.adroll.com https://d.adroll.com https://*.adswizz.com https://ads.revjet.com https://pix.revjet.com https://seal.verisign.com https://code.jquery.com https://snap.licdn.com; report-uri https://browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub16b313e1658347a16504b662a893cd7e&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=env%3Aproduction; report-to csp-endpoint;
Reporting-endpoints csp-endpoint="https://browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub16b313e1658347a16504b662a893cd7e&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=env%3Aproduction"
Content-length 9472
Strict-transport-security max-age=31536000