B
postman.com
Score 80/100 · scanned 2026-08-04Content-Security-Policy
No enforcing Content-Security-Policy on the homepage response. What that means →
Headers sent
| Header | Value |
|---|---|
content-security-policy-report-only | default-src 'self' data: blob: https://067-umd-991.mktoresp.com https://accounts.google.com https://analytics.google.com https://api.amplitude.com https://bi-beta.pst.tech https://bi.pst.tech https://… |
strict-transport-security | max-age=31536000; includeSubDomains; preload |
x-frame-options | SAMEORIGIN |
x-content-type-options | nosniff |
referrer-policy | strict-origin-when-cross-origin |
x-xss-protection | 1; mode=block |
server | cloudflare |
access-control-allow-origin | * |
Re-scan live
This is a snapshot from 2026-08-04. Check it now: