Technical Information
| HTTP Status Code | 200 |
| HTTP Version | HTTP/1.1 |
| HTTPS | ✔ Available |
| IP Address | 23.39.245.87 |
| Compression | gzip |
|
ℹ 🔵 Missing X-Frame-Options | The site can be embedded in iframes by third parties (clickjacking risk). |
HTTP Status Code 200
HTTP Version HTTP/1.1
HTTPS ✔ Available
IP Address 23.39.245.87
Compression gzip
ℹ 🔵 Missing X-Frame-Options The site can be embedded in iframes by third parties (clickjacking risk).
Redirect Chain
| # | URL | HTTP Status Code | Status |
| 1 | https://subway.com:443 | 302 | HTTP/2 302 |
| 2 | https://subwayfrance.fr/ | 200 | HTTP/2 200 |
#1 URL https://subway.com:443
HTTP Status Code 302
Status HTTP/2 302
#2 URL https://subwayfrance.fr/
HTTP Status Code 200
Status HTTP/2 200
Performance
| DNS Lookup | 10.4 ms |
| TCP Connect | 12.2 ms |
| TLS Handshake | 4 ms |
| Time To First Byte (TTFB) | 47 ms |
| Content Download | 0.6 ms |
| Total Response Time | 47.6 ms |
DNS Lookup 10.4 ms
TCP Connect 12.2 ms
TLS Handshake 4 ms
Time To First Byte (TTFB) 47 ms
Content Download 0.6 ms
Total Response Time 47.6 ms
Security
| HTTPS | ✔ Enabled |
| HSTS | ✔ max-age=31536000; includeSubDomains; preload |
| CSP | ✔ Configured |
| X-Frame-Options | ⚠ Not configured |
| X-Content-Type-Options | ✔ nosniff |
| Referrer Policy | no-referrer |
| Permissions Policy | ✔ Configured |
| HTTP/2 | ⚠ HTTP/1.1 |
HTTPS ✔ Enabled
HSTS ✔ max-age=31536000; includeSubDomains; preload
CSP ✔ Configured
X-Frame-Options ⚠ Not configured
X-Content-Type-Options ✔ nosniff
Referrer Policy no-referrer
Permissions Policy ✔ Configured
HTTP/2 ⚠ HTTP/1.1
SEO Quick Check
| Title | Home | Subway France |
Title Home | Subway France
Detected Technologies
| Technology | React Google Analytics Google Tag Manager Next.js |
Technology React Google Analytics Google Tag Manager Next.js
HTTP Headers
| Content-security-policy
| default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://www.googletagmanager.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://www.instagram.com; connect-src 'self' https://www.googletagmanager.com https://www.google-analytics.com https://consent.cookiebot.com https://consentcdn.cookiebot.com; style-src 'self' 'unsafe-inline'; img-src https: 'self' blob: data:; font-src 'self'; frame-src https://www.googletagmanager.com https://consentcdn.cookiebot.com https://www.instagram.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' https://tagassistant.google.com; upgrade-insecure-requests; |
| X-permitted-cross-domain-policies
| none |
| Referrer-policy
| no-referrer |
| X-content-type-options
| nosniff |
| Permissions-policy
| autoplay=() |
| Strict-transport-security
| max-age=31536000; includeSubDomains; preload |
| X-powered-by
| Next.js |
| Cache-control
| private, no-cache, no-store, max-age=0, must-revalidate |
| Etag
| "14bqrssituf467z" |
| Content-type
| text/html; charset=utf-8 |
| Vary
| Accept-Encoding |
| Content-encoding
| gzip |
| Date
| Wed, 22 Jul 2026 09:16:26 GMT |
Meta Tags
| Viewport | width=device-width |
| Next-head-count | 13 |
Content-security-policy default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://www.googletagmanager.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://www.instagram.com; connect-src 'self' https://www.googletagmanager.com https://www.google-analytics.com https://consent.cookiebot.com https://consentcdn.cookiebot.com; style-src 'self' 'unsafe-inline'; img-src https: 'self' blob: data:; font-src 'self'; frame-src https://www.googletagmanager.com https://consentcdn.cookiebot.com https://www.instagram.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' https://tagassistant.google.com; upgrade-insecure-requests;
X-permitted-cross-domain-policies none
Referrer-policy no-referrer
X-content-type-options nosniff
Permissions-policy autoplay=()
Strict-transport-security max-age=31536000; includeSubDomains; preload
X-powered-by Next.js
Cache-control private, no-cache, no-store, max-age=0, must-revalidate
Etag "14bqrssituf467z"
Content-type text/html; charset=utf-8
Vary Accept-Encoding
Content-encoding gzip
Date Wed, 22 Jul 2026 09:16:26 GMT