Check Detail
muenchen.de · HEADER
Incomplete
Grade D
48.1%
Result Detail
HEADERAlerts
- Strict-Transport-Security: max-age=31557600 (not secure)
- X-Frame-Options: Header missing
- Permissions-Policy: Permissions-Policy missing
- Cross-Origin-Opener-Policy: Header missing
- Cross-Origin-Embedder-Policy: Header missing
- Cross-Origin-Resource-Policy: Header missing
- Expect-CT: Expect-CT missing
- X-Permitted-Cross-Domain-Policies: Header missing
- Access-Control-Allow-Origin: Access-Control-Allow-Origin missing
- Origin-Agent-Cluster: Header missing
Normalized headers
cache-control | max-age=60, public, s-maxage=86400, stale-if-error=86400, stale-while-revalidate=60 |
---|---|
content-language | de |
content-security-policy | frame-ancestors 'self' https://move.mvg.de; report-uri /report-csp-violation |
content-type | text/html; charset=UTF-8 |
etag | "1760551263" |
expires | Sun, 19 Nov 1978 05:00:00 GMT |
last-modified | Wed, 15 Oct 2025 18:01:03 GMT |
referrer-policy | no-referrer |
traceresponse | 00-186ebc0bdc7fa5dc7bcb1189c06ebbc1-87dc02724dd10293-01 |
x-content-type-options | nosniff |
x-debug-info | eyJyZXRyaWVzIjowfQ== |
x-platform-cluster | uvlniuusfgpia-main-bvxea6i |
x-platform-processor | tca32zazg45hwegnnqdrakd6j4 |
x-platform-router | vx7hat5k4ld4whmvf5ovac4amm |
x-xss-protection | 1; mode=block |
accept-ranges | bytes |
age | 7761 |
date | Wed, 15 Oct 2025 20:10:24 GMT |
x-served-by | cache-fra-etou8220070-FRA, cache-muc13947-MUC |
x-cache | HIT, HIT |
x-cache-hits | 24, 0 |
vary | Cookie, Accept-Encoding |
strict-transport-security | max-age=31557600 |
content-length | 271059 |
Transport
Check name | Status | Actual | Expected | Detail | Severity | Recommendation |
---|---|---|---|---|---|---|
Strict-Transport-Security | ⚠️ Attention | max-age=31557600 | max-age>=15768000; includeSubDomains; preload | max-age=31557600 (not secure) | Critical | Strict-Transport-Security: max-age=63072000; includeSubDomains; preload |
Expect-CT | ⚠️ Attention | enforce; max-age>=86400 | Expect-CT missing | Medium | Expect-CT: enforce, max-age=86400, report-uri="https://report.example.com" |
Content Security
Check name | Status | Actual | Expected | Detail | Severity | Recommendation |
---|---|---|---|---|---|---|
Content-Security-Policy | ✅ OK | frame-ancestors 'self' https://move.mvg.de; report-uri /report-csp-violation | default-src 'self'; frame-ancestors 'none' | default-src 'self'; frame-ancestors 'none' | Critical | Content-Security-Policy: default-src 'self'; frame-ancestors 'none' |
MIME
Check name | Status | Actual | Expected | Detail | Severity | Recommendation |
---|---|---|---|---|---|---|
X-Content-Type-Options | ✅ OK | nosniff | nosniff | Value matches recommendation | High | X-Content-Type-Options: nosniff |
Framing
Check name | Status | Actual | Expected | Detail | Severity | Recommendation |
---|---|---|---|---|---|---|
X-Frame-Options | ⚠️ Attention | DENY or SAMEORIGIN | Header missing | High | X-Frame-Options: DENY |
Privacy
Check name | Status | Actual | Expected | Detail | Severity | Recommendation |
---|---|---|---|---|---|---|
Referrer-Policy | ✅ OK | no-referrer | strict-origin-when-cross-origin / same-origin | strict-origin-when-cross-origin | Medium | Referrer-Policy: strict-origin-when-cross-origin |
Browser Features
Check name | Status | Actual | Expected | Detail | Severity | Recommendation |
---|---|---|---|---|---|---|
Permissions-Policy | ⚠️ Attention | camera=(); geolocation=(); microphone=() | Permissions-Policy missing | Medium | Permissions-Policy: camera=(), geolocation=(), microphone=() |
Cross-Origin
Check name | Status | Actual | Expected | Detail | Severity | Recommendation |
---|---|---|---|---|---|---|
Cross-Origin-Opener-Policy | ⚠️ Attention | same-origin | Header missing | High | Cross-Origin-Opener-Policy: same-origin | |
Cross-Origin-Embedder-Policy | ⚠️ Attention | require-corp | Header missing | High | Cross-Origin-Embedder-Policy: require-corp | |
Cross-Origin-Resource-Policy | ⚠️ Attention | same-origin | Header missing | Medium | Cross-Origin-Resource-Policy: same-origin | |
Origin-Agent-Cluster | ⚠️ Attention | ?1 | Header missing | Low | Origin-Agent-Cluster: ?1 |
Caching
Check name | Status | Actual | Expected | Detail | Severity | Recommendation |
---|---|---|---|---|---|---|
Cache-Control | ✅ OK | max-age=60, public, s-maxage=86400, stale-if-error=86400, stale-while-revalidate=60 | no-store, private, max-age=0 | no-store, private, max-age=0 | High | Cache-Control: no-store, private, max-age=0 |
Legacy
Check name | Status | Actual | Expected | Detail | Severity | Recommendation |
---|---|---|---|---|---|---|
X-Permitted-Cross-Domain-Policies | ⚠️ Attention | none | Header missing | Low | X-Permitted-Cross-Domain-Policies: none |
CORS
Check name | Status | Actual | Expected | Detail | Severity | Recommendation |
---|---|---|---|---|---|---|
Access-Control-Allow-Origin | ⚠️ Attention | Scoped origin (no wildcard) | Access-Control-Allow-Origin missing | Medium | Access-Control-Allow-Origin: https://app.example.com |
Information Disclosure
Check name | Status | Actual | Expected | Detail | Severity | Recommendation |
---|---|---|---|---|---|---|
Server | ✅ OK | Header removed or generic | Header not exposed | High | Remove Server header or set to a generic token | |
X-Powered-By | ✅ OK | Header removed | Header not exposed | High | Remove X-Powered-By header | |
X-AspNet-Version | ✅ OK | Header removed | Header not exposed | Medium | Remove framework version headers |
Raw headers
HTTP/2 200 cache-control: max-age=60, public, s-maxage=86400, stale-if-error=86400, stale-while-revalidate=60 content-language: de content-security-policy: frame-ancestors 'self' https://move.mvg.de; report-uri /report-csp-violation content-type: text/html; charset=UTF-8 etag: "1760551263" expires: Sun, 19 Nov 1978 05:00:00 GMT last-modified: Wed, 15 Oct 2025 18:01:03 GMT referrer-policy: no-referrer traceresponse: 00-186ebc0bdc7fa5dc7bcb1189c06ebbc1-87dc02724dd10293-01 x-content-type-options: nosniff x-debug-info: eyJyZXRyaWVzIjowfQ== x-platform-cluster: uvlniuusfgpia-main-bvxea6i x-platform-processor: tca32zazg45hwegnnqdrakd6j4 x-platform-router: vx7hat5k4ld4whmvf5ovac4amm x-xss-protection: 1; mode=block accept-ranges: bytes age: 7761 date: Wed, 15 Oct 2025 20:10:24 GMT x-served-by: cache-fra-etou8220070-FRA, cache-muc13947-MUC x-cache: HIT, HIT x-cache-hits: 24, 0 vary: Cookie, Accept-Encoding strict-transport-security: max-age=31557600 content-length: 271059