HTTP Headers Analyzer
6 / 10
http://sportpesa.co.tz/
Website → Nginx → Browser9 missing headers, 0 warnings, 3 notices
Header
Value
Explanation
server
nginx/1.21.5
date
tue, 23 dec 2025 22:20:55 gmt
The date and time at which the request was made. A browser uses it for age calculations rather than using its own internal date and time; e.g. when comparing against
Max-Age or Expires.connection
close
Specifies whether the network connection stays open after the current request.
keep-alive specifies that the browser would like to keep the connection open, while close indicates that the browser wants to close the connection.vary
accept-encoding
The
Vary header specifies a list of headers that must be considered when caching responses. For a cached response to be used, these headers must match between the cached response and the new request. This ensures that the appropriate version of a resource is served based on factors like language, encoding, or device type.vary
accept-language
The
Vary header specifies a list of headers that must be considered when caching responses. For a cached response to be used, these headers must match between the cached response and the new request. This ensures that the appropriate version of a resource is served based on factors like language, encoding, or device type.set-cookie
sptzssid=eb26da845f2aafabfe1058e3cfc38d2f; expires=thu, 22-jan-2026 22:19:14 gmt; max-age=2592000; path=/; secure; httponly; samesite=lax
A cookie that was sent from the server to the browser.
Notice
expires= sets the maximum lifetime of the cookie using a specific date.max-age= sets the maximum lifetime of the cookie in seconds.path= indicates the path that must exist in the requested URL for the browser to send the cookie.Notice
samesite=lax instructs the browser not to share the cookie with third-party sites (e.g. when loading images, videos or frames from other sites), with one exception. The cookie will be sent when a user is navigating to the origin site from an external site (for example, when following a link). To improve protection against cross-site request forgery attacks, set to samesite=strict.secure instructs the browser to only send the cookie back when HTTPS requests are used, making it more resistant to man-in-the-middle attacks.httponly forbids JavaScript from accessing the cookie. Helps mitigate the risk of client side scripts accessing a protected cookie.set-cookie
device_view=full; expires=fri, 23-jan-2026 22:19:14 gmt; max-age=2678400; path=/; secure; httponly
A cookie that was sent from the server to the browser.
expires= sets the maximum lifetime of the cookie using a specific date.max-age= sets the maximum lifetime of the cookie in seconds.path= indicates the path that must exist in the requested URL for the browser to send the cookie.secure instructs the browser to only send the cookie back when HTTPS requests are used, making it more resistant to man-in-the-middle attacks.httponly forbids JavaScript from accessing the cookie. Helps mitigate the risk of client side scripts accessing a protected cookie.set-cookie
visited=1; expires=thu, 23-dec-2027 22:19:14 gmt; max-age=63072000; path=/; secure; httponly; samesite=lax
A cookie that was sent from the server to the browser.
Notice
expires= sets the maximum lifetime of the cookie using a specific date.max-age= sets the maximum lifetime of the cookie in seconds.path= indicates the path that must exist in the requested URL for the browser to send the cookie.Notice
samesite=lax instructs the browser not to share the cookie with third-party sites (e.g. when loading images, videos or frames from other sites), with one exception. The cookie will be sent when a user is navigating to the origin site from an external site (for example, when following a link). To improve protection against cross-site request forgery attacks, set to samesite=strict.secure instructs the browser to only send the cookie back when HTTPS requests are used, making it more resistant to man-in-the-middle attacks.httponly forbids JavaScript from accessing the cookie. Helps mitigate the risk of client side scripts accessing a protected cookie.set-cookie
locale=sw; expires=wed, 24-dec-2025 22:19:14 gmt; max-age=86400; path=/; secure
A cookie that was sent from the server to the browser.
expires= sets the maximum lifetime of the cookie using a specific date.max-age= sets the maximum lifetime of the cookie in seconds.path= indicates the path that must exist in the requested URL for the browser to send the cookie.secure instructs the browser to only send the cookie back when HTTPS requests are used, making it more resistant to man-in-the-middle attacks.cache-control
max-age=0, must-revalidate, private
private means the response can only be stored by the browser's cache, but not by CDNs, proxies, or any other shared caches.max-age=0 with must-revalidate means caching is disabled and all requests must be validated with the origin server.expires
tue, 23 dec 2025 22:19:14 gmt
This
Notice Because there is a
Expires date is in the past: the page is considered stale and will be removed from all caches.Notice Because there is a
Cache-Control header with a max-age and/or s-maxage directive, the Expires header will be ignored. Consider removing Expires to save bandwidth and processing power.strict-transport-security
missing Add a
Strict-Transport-Security header. The Strict-Transport-Security header or HSTS header is used to instruct browsers to only use HTTPS, instead of using HTTP. It helps enforce secure communication.content-security-policy
missing Add a
Content-Security-Policy header. The Content-Security-Policy header helps browsers prevent cross site scripting (XSS) and data injection attacks.referrer-policy
missing Add a
Referrer-Policy header. When a visitor navigates from one page to another, browsers often pass along referrer information. The Referrer-Policy header controls how much referrer information a browser can share. This is important to configure when private information is embedded in the path or query string and passed onto an external destination.permissions-policy
missing Add a
Permissions-Policy header. Restrict access to device features like the camera, microphone, location, accelerometer and much more.cross-origin-embedder-policy
missing Add a
Cross-Origin-Embedder-Policy to specify how this page can be loaded by cross-origin resources.cross-origin-opener-policy
missing Add a
Cross-Origin-Opener-Policy header to opt-in into better browser isolation.cross-origin-resource-policy
missing Add a
Cross-Origin-Resource-Policy header to specify who can load this page.x-frame-options
missing Add a
X-Frame-Options header. The X-Frame-Options header prevents this URL from being embedded in an iframe. This protects against clickjacking attacks. Alternatively, set a Content-Security-Policy header with a frame-ancestor directive.x-permitted-cross-domain-policies
missing Add a
X-Permitted-Cross-Domain-Policies header to prevent Flash, Adobe Reader and other clients from sharing data across domains.Questions or feedback? Email dries@buytaert.net.