Technical Information
| HTTP Status Code | 200 |
| HTTP Version | HTTP/1.1 |
| HTTPS | ✔ Available |
| IP Address | 128.140.39.58 |
| Compression | gzip |
|
ℹ 🔵 Missing Content Security Policy | CSP is not configured. It helps prevent XSS attacks and content injection. |
|
ℹ 🔵 Missing X-Frame-Options | The site can be embedded in iframes by third parties (clickjacking risk). |
HTTP Status Code 200
HTTP Version HTTP/1.1
HTTPS ✔ Available
IP Address 128.140.39.58
Compression gzip
ℹ 🔵 Missing Content Security Policy CSP is not configured. It helps prevent XSS attacks and content injection.
ℹ 🔵 Missing X-Frame-Options The site can be embedded in iframes by third parties (clickjacking risk).
Performance
| DNS Lookup | 29.1 ms |
| TCP Connect | 40.6 ms |
| TLS Handshake | 24.9 ms |
| Time To First Byte (TTFB) | 78.7 ms |
| Content Download | 49.5 ms |
| Total Response Time | 128.2 ms |
DNS Lookup 29.1 ms
TCP Connect 40.6 ms
TLS Handshake 24.9 ms
Time To First Byte (TTFB) 78.7 ms
Content Download 49.5 ms
Total Response Time 128.2 ms
Security
| HTTPS | ✔ Enabled |
| HSTS | ✔ max-age=16070400; includeSubDomains; preload |
| CSP | ⚠ Not configured |
| X-Frame-Options | ⚠ Not configured |
| X-Content-Type-Options | ⚠ Not configured |
| HTTP/2 | ⚠ HTTP/1.1 |
HTTPS ✔ Enabled
HSTS ✔ max-age=16070400; includeSubDomains; preload
CSP ⚠ Not configured
X-Frame-Options ⚠ Not configured
X-Content-Type-Options ⚠ Not configured
HTTP/2 ⚠ HTTP/1.1
Detected Technologies
| Technology | Vue.js Node.js |
Technology Vue.js Node.js
HTTP Headers
| X-Powered-By
| Express |
| Sys
| MyCMS |
| Access-Control-Allow-Origin
| * |
| Access-Control-Allow-Headers
| Origin, X-Requested-With, Content-Type, Accept, App-Auth |
| Strict-Transport-Security
| max-age=16070400; includeSubDomains; preload |
| Content-Type
| text/html; charset=utf-8 |
| ETag
| W/"213-87NAFgzx8/QxT6d3tC5CgVAsWaE" |
| Vary
| Accept-Encoding |
| Content-Encoding
| gzip |
| Date
| Wed, 22 Jul 2026 13:57:08 GMT |
| Connection
| keep-alive |
| Keep-Alive
| timeout=5 |
| Transfer-Encoding
| chunked |
X-Powered-By Express
Sys MyCMS
Access-Control-Allow-Origin *
Access-Control-Allow-Headers Origin, X-Requested-With, Content-Type, Accept, App-Auth
Strict-Transport-Security max-age=16070400; includeSubDomains; preload
Content-Type text/html; charset=utf-8
ETag W/"213-87NAFgzx8/QxT6d3tC5CgVAsWaE"
Vary Accept-Encoding
Content-Encoding gzip
Date Wed, 22 Jul 2026 13:57:08 GMT
Connection keep-alive
Keep-Alive timeout=5
Transfer-Encoding chunked