Security Report Summary
D
Site: https://gtrsocials.com/tools/twitter-media-downloader
IP Address: 172.66.43.45
Report Time: 05 Sep 2026 09:12:16 UTC
Headers:
  • X-Content-Type-Options
  • Content-Security-Policy
  • X-Frame-Options
  • Referrer-Policy
  • Permissions-Policy
  • Strict-Transport-Security
Advanced:
Your site could be at risk, let’s perform a deeper security analysis of your site and APIs:
Missing Headers
Content-Security-PolicyContent Security Policy is an effective measure to protect your site from XSS attacks. By whitelisting sources of approved content, you can prevent the browser from loading malicious assets.
X-Frame-OptionsX-Frame-Options tells the browser whether you want to allow your site to be framed or not. By preventing a browser from framing your site you can defend against attacks like clickjacking. Recommended value "X-Frame-Options: SAMEORIGIN".
Referrer-PolicyReferrer Policy is a new header that allows a site to control how much information the browser includes with navigations away from a document and should be set by all sites.
Permissions-PolicyPermissions Policy is a new header that allows a site to control which features and APIs can be used in the browser.
Warnings
Strict-Transport-SecurityThe "max-age" directive is too small. The minimum recommended value is 2592000 (30 days).
Raw Headers
HTTP/2200
dateSat, 05 Sep 2026 09:12:16 GMT
content-typetext/html; charset=UTF-8
servercloudflare
nel{"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
report-to{"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=yN39RtMtaMZ0an07zSxo4%2B%2FrcIdpl1%2F1RUSIQTWsQS99kRoDrkL%2FojSMJruZrNX%2BoJxzW0kyAAiX08Ko3w27U3CLM5lV6CM7CRZHTFm8GiNkDkfYdwBcf8a4gEcHT1il"}]}
varyAccept-Encoding
cache-controlno-cache, private
set-cookieXSRF-TOKEN=eyJpdiI6IkxDMUcrOTNmRElTNkROdGRlazZ5amc9PSIsInZhbHVlIjoiWWx0bkpKUVVLd2k4MTJLVUk3YlhQVFBjcHByQ010LzlLazlJcG5ZUU0vZDR0K2M2bkFzS0l4cEptbUNKTzA5dEtRMmt5VUhEdnIrc1BkYlpIcjgwVWlGa3VSeEZlR0tXZXpBMklyenlSR21zVVVEdVppQTBJRG9LNi80QWpQRlYiLCJtYWMiOiJiYjEzMTAwNDZmYjg1MzcxM2UzMWIwZTM0MzU1NThhNjIwMmZjNTZiZTEyYzkwZjcxNmI0YTY1NTRhMzNhMWUxIiwidGFnIjoiIn0%3D; expires=Mon, 05 Oct 2026 09:12:16 GMT; Max-Age=2592000; path=/; secure; samesite=lax
set-cookiegtrsocials_session=eyJpdiI6InI5NkE5L2hrRTFSNEtpVFBEcmlteVE9PSIsInZhbHVlIjoiK01OUit5L0Y4T1lhUTZKZVdBd2tyWHhIWVNja0NKSVpWWWUvOHVES1N1YzN6K1lSbEF5NWNRdDBGRGxNb0o2dHo2VEU3VnNRTWZKVDdUWVlOdHZMYU5OaGFQYy9JZzlSMHFPeFd4d0dBdVNMRVpjSnF3OWVmZDFzeDgxUU05RUciLCJtYWMiOiI1MjI0YWUxZjU5ZWI2MGM0YjI4YTFjNzAzMzUyNzgzMmEwZTYzMmRhYjhlYTc5NTNkNmVhZmQzODVkMGNhOWNjIiwidGFnIjoiIn0%3D; expires=Mon, 05 Oct 2026 09:12:16 GMT; Max-Age=2592000; path=/; httponly; samesite=lax
set-cookiegtr_did=eyJpdiI6InVhT0dzaE8xeWg3WDdCRzVpK09UMnc9PSIsInZhbHVlIjoiNEhHREQ5UitkU1RlUE50MHgvcmx4OERQd1BpVSsxbXhlNVdvRWhBN1pWMkF2dHZWWlYxeGIzSjdVcUdIdGc4Zmc1T251dS9TYjkyc29EZWV6clN6L1MrU3ltRGFzWkY4R3YxT2xNTFlyWEk9IiwibWFjIjoiYmVhZjcyMWY5MTU4MTE3ZTgwOTAxMmVmNzdiNmM1MTlhNTJiYmVlZGYyZTk1MTRiMDcwOWIzZThjNjg4YmVlMCIsInRhZyI6IiJ9; expires=Mon, 04 Sep 2028 09:12:16 GMT; Max-Age=63072000; path=/; secure; httponly; samesite=lax
set-cookiegtr_cid=eyJpdiI6IlB5UTJpZlY3T3ZvVjlETVdMSUpmbHc9PSIsInZhbHVlIjoibHgwbzE3THpiOUJ6RTZ1bVUya3ppZ2ROcFhidzY3SlJaaXZqV2M3b3VjalR6UG1NM3Ixb051R2FadDhtNkp1TlN4MytURnJIS3oxa0V6djhSVTYyZW9ZdC8rdUFtTHV6bG5pS005K1BaMzA9IiwibWFjIjoiMGJlMzA5OWM4ZTk5YjU4NzY5NTM5N2NiM2Y3MjNjMjIwM2QzNzVmNWRjNWFhZjIyNWUyZjdhOGM3MTczY2U1ZiIsInRhZyI6IiJ9; expires=Mon, 04 Sep 2028 09:12:16 GMT; Max-Age=63072000; path=/; secure; httponly; samesite=lax
speculation-rules"/cdn-cgi/speculation"
cf-cache-statusDYNAMIC
strict-transport-securitymax-age=0; includeSubDomains; preload
x-content-type-optionsnosniff
content-encodinggzip
cf-raya3641c7cddd189e5-DUB
alt-svch3=":443"; ma=86400
Upcoming Headers
Cross-Origin-Embedder-PolicyCross-Origin Embedder Policy allows a site to prevent assets being loaded that do not grant permission to load them via CORS or CORP.
Cross-Origin-Opener-PolicyCross-Origin Opener Policy allows a site to opt-in to Cross-Origin Isolation in the browser.
Cross-Origin-Resource-PolicyCross-Origin Resource Policy allows a resource owner to specify who can load the resource.
Additional Information
serverServer value has been changed. Typically you will see values like "Microsoft-IIS/8.0" or "nginx 1.7.2".
nelNetwork Error Logging is a new header that instructs the browser to send reports during various network or application errors. You can sign up for a free account on Report URI to collect these reports.
report-toReport-To enables the Reporting API. This allows a website to collect reports from the browser about various errors that may occur. You can sign up for a free account on Report URI to collect these reports.
set-cookieThe 'secure' flag is not set on this cookie. There is no Cookie Prefix on this cookie.
strict-transport-securityHTTP Strict Transport Security is an excellent feature to support on your site and strengthens your implementation of TLS by getting the User Agent to enforce the use of HTTPS.
x-content-type-optionsX-Content-Type-Options stops a browser from trying to MIME-sniff the content type and forces it to stick with the declared content-type. The only valid value for this header is "X-Content-Type-Options: nosniff".