Technical Information
| HTTP Status Code | 200 |
| HTTP Version | HTTP/1.1 |
| HTTPS | ✔ Available |
| IP Address | 128.95.160.154 |
| Server Software | nginx/1.25.5 |
|
🔒 🟡 Mixed Content (8 HTTP resources) | The page is served over HTTPS but loads 8 resource(s) over HTTP. This may be blocked in modern browsers. |
|
🕐 🟡 Slow Response (1336 ms) | Response time exceeds 1 second. Consider optimizing the server or using caching. |
|
ℹ 🔵 Missing HSTS | HTTP Strict Transport Security is not configured. Recommended for HTTPS sites. |
|
ℹ 🔵 Missing Content Security Policy | CSP is not configured. It helps prevent XSS attacks and content injection. |
|
ℹ 🔵 No Compression | The server does not use Gzip or Brotli. Enable compression to reduce bandwidth usage. |
HTTP Status Code 200
HTTP Version HTTP/1.1
HTTPS ✔ Available
IP Address 128.95.160.154
Server Software nginx/1.25.5
🔒 🟡 Mixed Content (8 HTTP resources) The page is served over HTTPS but loads 8 resource(s) over HTTP. This may be blocked in modern browsers.
🕐 🟡 Slow Response (1336 ms) Response time exceeds 1 second. Consider optimizing the server or using caching.
ℹ 🔵 Missing HSTS HTTP Strict Transport Security is not configured. Recommended for HTTPS sites.
ℹ 🔵 Missing Content Security Policy CSP is not configured. It helps prevent XSS attacks and content injection.
ℹ 🔵 No Compression The server does not use Gzip or Brotli. Enable compression to reduce bandwidth usage.
Performance
| DNS Lookup | 467.9 ms |
| TCP Connect | 612.1 ms |
| TLS Handshake | 151.7 ms |
| Time To First Byte (TTFB) | 1336 ms |
| Content Download | 0.1 ms |
| Total Response Time | 1336.1 ms |
DNS Lookup 467.9 ms
TCP Connect 612.1 ms
TLS Handshake 151.7 ms
Time To First Byte (TTFB) 1336 ms
Content Download 0.1 ms
Total Response Time 1336.1 ms
Security
| HTTPS | ✔ Enabled |
| HSTS | ✘ Not configured |
| CSP | ⚠ Not configured |
| X-Frame-Options | ✔ SAMEORIGIN |
| X-Content-Type-Options | ✔ nosniff |
| Referrer Policy | strict-origin-when-cross-origin |
| HTTP/2 | ⚠ HTTP/1.1 |
HTTPS ✔ Enabled
HSTS ✘ Not configured
CSP ⚠ Not configured
X-Frame-Options ✔ SAMEORIGIN
X-Content-Type-Options ✔ nosniff
Referrer Policy strict-origin-when-cross-origin
HTTP/2 ⚠ HTTP/1.1
SEO Quick Check
Title Foldit
Detected Technologies
| Technology | Google Analytics Nginx PHP Matomo |
Technology Google Analytics Nginx PHP Matomo
HTTP Headers
| Server
| nginx/1.25.5 |
| Date
| Wed, 19 Aug 2026 23:43:45 GMT |
| Content-Type
| text/html; charset=utf-8 |
| Transfer-Encoding
| chunked |
| Connection
| keep-alive |
| X-Frame-Options
| SAMEORIGIN |
| X-XSS-Protection
| 1; mode=block |
| X-Content-Type-Options
| nosniff |
| X-Download-Options
| noopen |
| X-Permitted-Cross-Domain-Policies
| none |
| Referrer-Policy
| strict-origin-when-cross-origin |
| ETag
| W/"ff15f86a53d96f38ee2415caef22b729" |
| Cache-Control
| max-age=0, private, must-revalidate |
| X-Request-Id
| f3525cef-f19d-40ce-8886-60c2d9e9be09 |
| X-Runtime
| 0.283176 |
Meta Tags
| Csrf-param | authenticity_token |
| Csrf-token | yqflWNAe6UG+ZT/oB4KI2b3RSyqTrH9KHowG+4zEcmoj4G6WIIfzL9k15Q15ZEPBTQyitcl8zu7vcTIs4+lKsw== |
| Viewport | width=device-width, initial-scale=1 |
Server nginx/1.25.5
Date Wed, 19 Aug 2026 23:43:45 GMT
Content-Type text/html; charset=utf-8
Transfer-Encoding chunked
Connection keep-alive
X-Frame-Options SAMEORIGIN
X-XSS-Protection 1; mode=block
X-Content-Type-Options nosniff
X-Download-Options noopen
X-Permitted-Cross-Domain-Policies none
Referrer-Policy strict-origin-when-cross-origin
ETag W/"ff15f86a53d96f38ee2415caef22b729"
Cache-Control max-age=0, private, must-revalidate
X-Request-Id f3525cef-f19d-40ce-8886-60c2d9e9be09
X-Runtime 0.283176