Current connection: Secure (HTTPS)
Forces HTTPS connections
Status: Not Set
Recommended: max-age=31536000; includeSubDomains; preload
Prevents clickjacking attacks
Status: Not Set
Recommended: SAMEORIGIN or DENY
Prevents MIME type sniffing
Status: Not Set
Recommended: nosniff
XSS filter in older browsers
Status: Not Set
Recommended: 1; mode=block
Controls resource loading
Status: Not Set
Recommended: Defined based on your needs
Controls referrer information
Status: Not Set
Recommended: strict-origin-when-cross-origin
Controls browser features
Status: Not Set
Recommended: Restrictive policy
Current Version: 8.4.12
Server header exposure is controlled
Current: nginx/1.23.2
Security Score: 2 / 9 checks passed