Technical Information
| HTTP Status Code | 200 |
| HTTP Version | HTTP/1.1 |
| HTTPS | ✔ Available |
| IP Address | 104.18.7.50 |
| Server Software | cloudflare |
| CDN | Cloudflare |
| Compression | gzip |
|
🕐 🟡 Slow Response (1190 ms) | Response time exceeds 1 second. Consider optimizing the server or using caching. |
|
ℹ 🔵 Missing X-Frame-Options | The site can be embedded in iframes by third parties (clickjacking risk). |
HTTP Status Code 200
HTTP Version HTTP/1.1
HTTPS ✔ Available
IP Address 104.18.7.50
Server Software cloudflare
CDN Cloudflare
Compression gzip
🕐 🟡 Slow Response (1190 ms) Response time exceeds 1 second. Consider optimizing the server or using caching.
ℹ 🔵 Missing X-Frame-Options The site can be embedded in iframes by third parties (clickjacking risk).
Redirect Chain
| # | URL | HTTP Status Code | Status |
| 1 | https://ucsfhealth.org:443 | 301 | HTTP/2 301 |
| 2 | https://www.ucsfhealth.org/ | 200 | HTTP/2 200 |
#1 URL https://ucsfhealth.org:443
HTTP Status Code 301
Status HTTP/2 301
#2 URL https://www.ucsfhealth.org/
HTTP Status Code 200
Status HTTP/2 200
Performance
| DNS Lookup | 32.3 ms |
| TCP Connect | 34.2 ms |
| TLS Handshake | 7.1 ms |
| Time To First Byte (TTFB) | 886.2 ms |
| Content Download | 303.4 ms |
| Total Response Time | 1189.6 ms |
DNS Lookup 32.3 ms
TCP Connect 34.2 ms
TLS Handshake 7.1 ms
Time To First Byte (TTFB) 886.2 ms
Content Download 303.4 ms
Total Response Time 1189.6 ms
Security
| HTTPS | ✔ Enabled |
| HSTS | ✔ max-age=63072000; includeSubDomains; preload |
| CSP | ✔ Configured |
| X-Frame-Options | ⚠ Not configured |
| X-Content-Type-Options | ✔ nosniff |
| Referrer Policy | strict-origin-when-cross-origin |
| Permissions Policy | ✔ Configured |
| HTTP/2 | ⚠ HTTP/1.1 |
HTTPS ✔ Enabled
HSTS ✔ max-age=63072000; includeSubDomains; preload
CSP ✔ Configured
X-Frame-Options ⚠ Not configured
X-Content-Type-Options ✔ nosniff
Referrer Policy strict-origin-when-cross-origin
Permissions Policy ✔ Configured
HTTP/2 ⚠ HTTP/1.1
Detected Technologies
| Technology | React Google Analytics Cloudflare Node.js Next.js |
Technology React Google Analytics Cloudflare Node.js Next.js
HTTP Headers
| Date
| Wed, 29 Jul 2026 04:20:51 GMT |
| Content-type
| text/html; charset=utf-8 |
| X-content-type-options
| nosniff |
| Referrer-policy
| strict-origin-when-cross-origin |
| Permissions-policy
| camera=(), microphone=(), geolocation=(self), interest-cohort=() |
| Strict-transport-security
| max-age=63072000; includeSubDomains; preload |
| Server
| cloudflare |
| X-powered-by
| |
| Content-security-policy
| frame-ancestors 'self' https://*.sitecorecloud.io https://*.sitecore.com http://localhost:3000 https://localhost:3000 |
| X-sc-rewrite
| /_site_UCSF/ |
| X-middleware-rewrite
| /en/_site_UCSF |
| X-nextjs-cache
| HIT |
| Cache-control
| s-maxage=1800, stale-while-revalidate=31534200 |
| Vary
| Accept-Encoding |
| Set-cookie
| x-cookie-consent=false; Path=/; Secure; SameSite=lax |
| Cf-cache-status
| DYNAMIC |
| Content-encoding
| gzip |
| Cf-ray
| a229555778a6d146-CDG |
Meta Tags
| Viewport | width=device-width, initial-scale=1 |
| Robots | index, follow |
Date Wed, 29 Jul 2026 04:20:51 GMT
Content-type text/html; charset=utf-8
X-content-type-options nosniff
Referrer-policy strict-origin-when-cross-origin
Permissions-policy camera=(), microphone=(), geolocation=(self), interest-cohort=()
Strict-transport-security max-age=63072000; includeSubDomains; preload
Server cloudflare
X-powered-by
Content-security-policy frame-ancestors 'self' https://*.sitecorecloud.io https://*.sitecore.com http://localhost:3000 https://localhost:3000
X-sc-rewrite /_site_UCSF/
X-middleware-rewrite /en/_site_UCSF
X-nextjs-cache HIT
Cache-control s-maxage=1800, stale-while-revalidate=31534200
Vary Accept-Encoding
Set-cookie x-cookie-consent=false; Path=/; Secure; SameSite=lax
Cf-cache-status DYNAMIC
Content-encoding gzip
Cf-ray a229555778a6d146-CDG