HTTP Headers for techcrunch.com

Responds with HTTP 200 from nginx — 6 of 6 security headers present.

Domain to Check
200 https://techcrunch.com/
Security Headers6/6
HSTS
CSP
X-Frame-Options
X-Content-Type-Options
Referrer-Policy
Permissions-Policy
All Response Headers (22)
accept-rangesbytes
access-control-allow-methods*
access-control-allow-originhttps://techcrunch.com
cache-controlmax-age=300, must-revalidate
connectionclose
content-encodingbr
content-security-policydefault-src 'self' *.techcrunch.com; frame-ancestors 'self'; frame-src 'self' https: data:; style-src 'self' 'unsafe-inline' *; img-src 'self' * data:; connect-src 'self' https:; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *; worker-src 'self' blob:; media-src 'self' blob: *.youtube.com *.jetpackdigital.com *.jwplayer.com *.jwpsrv.com; font-src 'self' * data:; upgrade-insecure-requests; block-all-mixed-content; sandbox allow-forms allow-same-origin allow-scripts allow-popups allow-popups-to-escape-sandbox;
content-typetext/html; charset=UTF-8
dateFri, 24 Apr 2026 15:21:04 GMT
host-headera9130478a60e5f9135f765b23f26593b
link<https://techcrunch.com/wp-json/>; rel="https://api.w.org/"
permissions-policyautoplay=(), camera=(), fullscreen=*, geolocation=*, display-capture=(self), microphone=()
referrer-policyno-referrer-when-downgrade
servernginx
strict-transport-securitymax-age=300;includeSubdomains
varyAccept-Encoding, Origin
x-cacheHIT
x-content-type-optionsnosniff
x-frame-optionsSAMEORIGIN
x-hackerIf you're reading this, you should visit https://join.a8c.com/viphacker and apply to join the fun, mention this header.
x-powered-byWordPress VIP <https://wpvip.com>
x-rqdca8 181 249 80
Related