Security Report Summary
D
| Site: | https://connect.garmin.com/app/profile/3a1b86c2-2f29-4e6d-82d4-191e39389760 | ||
|---|---|---|---|
| IP Address: | 104.17.168.14 | ||
| Report Time: | 29 Aug 2026 07:16:53 UTC | ||
| Headers: |
|
||
| Advanced: |
|
Missing Headers
| Content-Security-Policy | Content Security Policy is an effective measure to protect your site from XSS attacks. By whitelisting sources of approved content, you can prevent the browser from loading malicious assets. |
|---|---|
| X-Frame-Options | X-Frame-Options tells the browser whether you want to allow your site to be framed or not. By preventing a browser from framing your site you can defend against attacks like clickjacking. Recommended value "X-Frame-Options: SAMEORIGIN". |
| X-Content-Type-Options | X-Content-Type-Options stops a browser from trying to MIME-sniff the content type and forces it to stick with the declared content-type. The only valid value for this header is "X-Content-Type-Options: nosniff". |
| Referrer-Policy | Referrer Policy is a new header that allows a site to control how much information the browser includes with navigations away from a document and should be set by all sites. |
| Permissions-Policy | Permissions Policy is a new header that allows a site to control which features and APIs can be used in the browser. |
Raw Headers
| HTTP/2 | 200 |
|---|---|
| date | Sat, 29 Aug 2026 07:16:53 GMT |
| content-type | text/html; charset=UTF-8 |
| set-cookie | session=Fe26.2*1*5878912abf6f40fcf360f18c79150d77c4c50d03f9633379689e079a920114db*Ea27E9NacUddOkjWXPdoIw*qSvzp9ZZttpeDPpmiq4M5gUcU5wRXx8Q8RxNWOujWxWCnQswJn3OzxLzQN3wXHNIujYfQ1LLhDHHC0f8hqduogsZ-2yzx3Elqbf1T-4T2Q6nouFUrSJL658Ui7t8-4JcFGZs6mm04QAgUbVAUaJIYgTsrSh5K8LM8GEYhmvIdTf3vNckHEoAEpjQkl83-15u_31yEdWoyaFO7fJuxDfv-c92yoxTs_vmoZL3QYNMEjqH_u9X_-OW6pA3WanqRIDrTmOsdmz2Y6S8nfgHGJsfaXWw6-rUqt6V7vH3MWTSDVbjbM-erlh4hTC_vp-6O7iVdtLuxBBS7MhykbRGWk1KJ6-92qFhVg35Mjak9yOUiw2zUo8puumlro3kzZa730-p7xHqWj3NwTBPmDnBVTFLzp1rdkGmB_eHISsPsG2RVBgKxRjtjWvCs_GX1nHf4oSbW6AGtI2i6QQtccmHJnCb0kSV53TSi9NKh63DMg7VWe4otOzbapM-yUhbk_5THtAHlDzIakkjiljUWVEWuKKbqQgMg4el6ZnCNKM9oLlT-BC3lkx-t6y5r053nqo2c-r4PfjNRJrotc1PYgAlaNopKuDaki6Dp1EPKnIUMElIbmqGpbUU5Wbh-M97DOkzQus8ZY3sUVog4eEpkNXK7l8MNtHk4mrgR3PfW8Vw27XGVzmYjKnNnTDxymgo5e-CJ5RAz5m4biVBgIqrtpWid7UMoni-f6jMGwYv-u4TE4BDF-0bPiMCcel4tyMGNGiSMMjYde-7T3pKEwMEtjfQGUIhQ6m841Zx9qhtNOki019Uz-YIF4ApFDwxb_E94CmtKjbfHaQ_I8_9jMhvy6Jcm0peeM6rvVkeAKFpDHswK14Qdon5ZeeiJx7Cphc2gGZbxqZvNbg1e_pX7VM8ZlOBPuG_BmhMOZ-1wDKJWVAjua-Ufwo6jmmUB6QerknVV4Cy7TGTIZR2EnzyaihfVLUjidooQfeX2-moo_UDxox3nKmjNwVsWeg3MM29unf7yHd9GQ6Grgt94PbvamC6rg-qaT_vB7Jtq2h3LmT2Yi99QoOwOf9w6orl0Oc1mIsJ0kijNOVQEAUlal8aqkSVk8Vi8Lvs6f3LMkXBtTyjpAJT0IBF6Fsfvd2oUSbxY23erPk-nOI_j9M9TBFUq6ummv85E3NCb6BgMiZ5QuIuS_9P1bDHnWEx5yO2DBNgRZsFaR6OoopzN1a976hlTl01bx7jGe17EYMBKvO2uEekVfumfJDYJQGsF9gQXfbgNcR5pmxYm6SYTOviow2m_2txOvAKwJUh9g**a052640c2b9690678bd1e55da774393cd4d5f6aa5cdec6c900e0ed38d91d3580*hvXVJrU5GkntLnCpIy2Axh4_8TRAs_4SJtSbSaEyBR8~2; Max-Age=3598; Path=/; HttpOnly; Secure |
| set-cookie | SESSIONID=YTY3YjdiZjEtNGMxNC00MTIyLWFiZTMtMjgyYzA2MzM5YTEy; Path=/; HttpOnly; Secure |
| set-cookie | __cflb=02DiuJLbVZHipNWxN8yY4F2auY6PLuBRr1tSd9sDXPtVr; HttpOnly; SameSite=None; Secure; Path=/; Expires=Sun, 30 Aug 2026 06:16:53 GMT |
| nel | {"report_to":"cf-nel","success_fraction":0.01,"max_age":604800} |
| strict-transport-security | max-age=31536000; includeSubDomains |
| cf-cache-status | DYNAMIC |
| server-timing | cfCacheStatus;desc="DYNAMIC" |
| server-timing | cfEdge;dur=6,cfOrigin;dur=517 |
| report-to | {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=muGPTBNaSkaNd%2FlbYxOMV2CSF6f3Z0QjXJ%2BlPp%2BHhiukLOm8v86uJ8oZBogNEie5MtxYljymd6BN6BGGh7oDmSw3SdfSqbFda%2BJjNwixe1mKnQoEz8KUGeXn2nq52OxUDVav7A%3D%3D"}]} |
| content-encoding | gzip |
| server | cloudflare |
| cf-ray | a329c5d95fadb22c-DUB |
Upcoming Headers
| Cross-Origin-Embedder-Policy | Cross-Origin Embedder Policy allows a site to prevent assets being loaded that do not grant permission to load them via CORS or CORP. |
|---|---|
| Cross-Origin-Opener-Policy | Cross-Origin Opener Policy allows a site to opt-in to Cross-Origin Isolation in the browser. |
| Cross-Origin-Resource-Policy | Cross-Origin Resource Policy allows a resource owner to specify who can load the resource. |
Additional Information
| set-cookie | There is no Cookie Prefix on this cookie. This is not a SameSite Cookie. |
|---|---|
| set-cookie | There is no Cookie Prefix on this cookie. This is not a SameSite Cookie. |
| nel | Network Error Logging is a new header that instructs the browser to send reports during various network or application errors. You can sign up for a free account on Report URI to collect these reports. |
| strict-transport-security | HTTP Strict Transport Security is an excellent feature to support on your site and strengthens your implementation of TLS by getting the User Agent to enforce the use of HTTPS. |
| report-to | Report-To enables the Reporting API. This allows a website to collect reports from the browser about various errors that may occur. You can sign up for a free account on Report URI to collect these reports. |
| server | Server value has been changed. Typically you will see values like "Microsoft-IIS/8.0" or "nginx 1.7.2". |