HTTP Headers for walmart.com

Responds with HTTP 200 — 4 of 6 security headers present.

Domain to Check
200 https://www.walmart.com/
Security Headers4/6
HSTS
CSP
X-Frame-Options
X-Content-Type-Options
Referrer-Policy
Permissions-Policy
All Response Headers (26)
accept-chSec-CH-DPR, DPR, Sec-CH-Device-Memory, Device-Memory, Downlink
accept-rangesbytes
cache-controlmax-age=0, no-cache, no-store
cache-statusHit
connectionclose
content-encodinggzip
content-length184190
content-security-policyframe-ancestors 'self' *.wal.co *.walmart-customcards.com *.walmart.com:* *.walmart.net *.walmartimages.com; report-uri https://csp.walmart.com/c/r/gl
content-typetext/html; charset=utf-8
dateFri, 24 Apr 2026 14:59:53 GMT
expiresFri, 24 Apr 2026 14:59:53 GMT
mpulse_cdn_cacheHIT
mpulse_origin_time0
origin-cc
origin-ex
permissions-policych-dpr=(self "https://i5.walmartimages.com"), ch-device-memory=(self "https://i5.walmartimages.com")
pragmano-cache
server-timingproduct;desc="edge",host;desc="6fb0940bf545",dc;desc="a652627",fetch-ms;dur=1759,req-proc-ms;dur=50,resp-proc-ms;dur=14, ak_p; desc="1777042793233_389073140_553455815_51_16663_1_17_-";dur=1
set-cookieakavpau_p2=1777043393~id=8ffa68e9563ffd9ecdff1689f6eb6077; Path=/; HttpOnly; Secure; SameSite=None
strict-transport-securitymax-age=31536000
traceparent00-3e6117db0b5420826cc802acd6b5206b-7a118461f761bfbb-00
varyAccept-Encoding
x-envoy-upstream-service-time1758
x-frame-optionsSAMEORIGIN
x-opt-injtrue
x-tb0
Related