HTTP Headers for aistudio.google.com

Score

G

Recommendations

Missing HeaderDescription
Strict-Transport-SecurityEnforces secure (HTTP over SSL/TLS) connections to the server.
Content-Security-PolicyHelps prevent Cross-Site Scripting (XSS) attacks.
Referrer-PolicyControls how much referrer information should be included with requests.
Permissions-PolicyManages which browser features and APIs a page can use.
Expect-CTEnsures that browsers enforce Certificate Transparency.
Access-Control-Allow-OriginControls which origins are allowed to access resources on the server.

Header Issues

Header Issues

Header Issue
X-XSS-Protection should be 1; mode=block

Raw Headers

Header NameValue
Content-Typeapplication/binary
Cache-Controlno-cache, no-store, max-age=0, must-revalidate
Pragmano-cache
ExpiresMon, 01 Jan 1990 00:00:00 GMT
DateSun, 02 Mar 2025 11:45:57 GMT
Locationhttps://aistudio.google.com/
Content-Length0
ServerESF
X-XSS-Protection0
X-Frame-OptionsSAMEORIGIN
X-Content-Type-Optionsnosniff