Technical Information
| HTTP Status Code | 200 |
| HTTP Version | HTTP/1.1 |
| HTTPS | ✔ Available |
| IP Address | 128.95.160.154 |
| Server Software | nginx/1.25.5 |
|
🔒 🟡 Mixed Content (8 HTTP resources) | The page is served over HTTPS but loads 8 resource(s) over HTTP. This may be blocked in modern browsers. |
|
🕐 🟡 Slow Response (1029 ms) | Response time exceeds 1 second. Consider optimizing the server or using caching. |
|
ℹ 🔵 Missing HSTS | HTTP Strict Transport Security is not configured. Recommended for HTTPS sites. |
|
ℹ 🔵 Missing Content Security Policy | CSP is not configured. It helps prevent XSS attacks and content injection. |
|
ℹ 🔵 No Compression | The server does not use Gzip or Brotli. Enable compression to reduce bandwidth usage. |
HTTP Status Code 200
HTTP Version HTTP/1.1
HTTPS ✔ Available
IP Address 128.95.160.154
Server Software nginx/1.25.5
🔒 🟡 Mixed Content (8 HTTP resources) The page is served over HTTPS but loads 8 resource(s) over HTTP. This may be blocked in modern browsers.
🕐 🟡 Slow Response (1029 ms) Response time exceeds 1 second. Consider optimizing the server or using caching.
ℹ 🔵 Missing HSTS HTTP Strict Transport Security is not configured. Recommended for HTTPS sites.
ℹ 🔵 Missing Content Security Policy CSP is not configured. It helps prevent XSS attacks and content injection.
ℹ 🔵 No Compression The server does not use Gzip or Brotli. Enable compression to reduce bandwidth usage.
Performance
| DNS Lookup | 208.9 ms |
| TCP Connect | 352.9 ms |
| TLS Handshake | 151.5 ms |
| Time To First Byte (TTFB) | 1029.3 ms |
| Content Download | 0.1 ms |
| Total Response Time | 1029.3 ms |
DNS Lookup 208.9 ms
TCP Connect 352.9 ms
TLS Handshake 151.5 ms
Time To First Byte (TTFB) 1029.3 ms
Content Download 0.1 ms
Total Response Time 1029.3 ms
Security
| HTTPS | ✔ Enabled |
| HSTS | ✘ Not configured |
| CSP | ⚠ Not configured |
| X-Frame-Options | ✔ SAMEORIGIN |
| X-Content-Type-Options | ✔ nosniff |
| Referrer Policy | strict-origin-when-cross-origin |
| HTTP/2 | ⚠ HTTP/1.1 |
HTTPS ✔ Enabled
HSTS ✘ Not configured
CSP ⚠ Not configured
X-Frame-Options ✔ SAMEORIGIN
X-Content-Type-Options ✔ nosniff
Referrer Policy strict-origin-when-cross-origin
HTTP/2 ⚠ HTTP/1.1
SEO Quick Check
Title Foldit
Detected Technologies
| Technology | Google Analytics Nginx PHP Matomo |
Technology Google Analytics Nginx PHP Matomo
HTTP Headers
| Server
| nginx/1.25.5 |
| Date
| Thu, 20 Aug 2026 01:56:46 GMT |
| Content-Type
| text/html; charset=utf-8 |
| Transfer-Encoding
| chunked |
| Connection
| keep-alive |
| X-Frame-Options
| SAMEORIGIN |
| X-XSS-Protection
| 1; mode=block |
| X-Content-Type-Options
| nosniff |
| X-Download-Options
| noopen |
| X-Permitted-Cross-Domain-Policies
| none |
| Referrer-Policy
| strict-origin-when-cross-origin |
| ETag
| W/"9b08a068b418d3e2bd2464f480a7c1f8" |
| Cache-Control
| max-age=0, private, must-revalidate |
| X-Request-Id
| a6be5976-d981-4048-ab02-4c9d1fe32c76 |
| X-Runtime
| 0.236094 |
Meta Tags
| Csrf-param | authenticity_token |
| Csrf-token | VUJYoBGomgyVCCNwfDFEGeybWgjAkSz7BXQArz5eUehm1N+XLqkl+ILBeYheT981l/+d4KT6LmrE92Lf4gs97Q== |
| Viewport | width=device-width, initial-scale=1 |
Server nginx/1.25.5
Date Thu, 20 Aug 2026 01:56:46 GMT
Content-Type text/html; charset=utf-8
Transfer-Encoding chunked
Connection keep-alive
X-Frame-Options SAMEORIGIN
X-XSS-Protection 1; mode=block
X-Content-Type-Options nosniff
X-Download-Options noopen
X-Permitted-Cross-Domain-Policies none
Referrer-Policy strict-origin-when-cross-origin
ETag W/"9b08a068b418d3e2bd2464f480a7c1f8"
Cache-Control max-age=0, private, must-revalidate
X-Request-Id a6be5976-d981-4048-ab02-4c9d1fe32c76
X-Runtime 0.236094