Información Técnica
| Código de estado HTTP | 403 |
| Versión HTTP | HTTP/1.1 |
| HTTPS | ✔ Disponible |
| Dirección IP | 3.148.138.121 |
| Software del servidor | Apache |
|
🚫 🟡 HTTP 403 Error | El servidor devolvió un error 403. Revisa la configuración de acceso. |
|
ℹ 🔵 Falta X-Frame-Options | El sitio puede ser incrustado en iframes por terceros (riesgo de clickjacking). |
Código de estado HTTP 403
Versión HTTP HTTP/1.1
HTTPS ✔ Disponible
Dirección IP 3.148.138.121
Software del servidor Apache
🚫 🟡 HTTP 403 Error El servidor devolvió un error 403. Revisa la configuración de acceso.
ℹ 🔵 Falta X-Frame-Options El sitio puede ser incrustado en iframes por terceros (riesgo de clickjacking).
Rendimiento
| Resolución DNS | 4.1 ms |
| Conexión TCP | 97.8 ms |
| Negociación TLS | 99.2 ms |
| Tiempo hasta el primer byte (TTFB) | 291.4 ms |
| Descarga de contenido | 0 ms |
| Tiempo total de respuesta | 291.4 ms |
Resolución DNS 4.1 ms
Conexión TCP 97.8 ms
Negociación TLS 99.2 ms
Tiempo hasta el primer byte (TTFB) 291.4 ms
Descarga de contenido 0 ms
Tiempo total de respuesta 291.4 ms
Seguridad
| HTTPS | ✔ Activado |
| HSTS | ✔ max-age=31536000; includeSubDomains; preload |
| CSP | ✔ Configurado |
| X-Frame-Options | ⚠ No configurado |
| X-Content-Type-Options | ✔ nosniff |
| Política de Referrer | strict-origin-when-cross-origin |
| Política de Permisos | ✔ Configurado |
| HTTP/2 | ⚠ HTTP/1.1 |
HTTPS ✔ Activado
HSTS ✔ max-age=31536000; includeSubDomains; preload
CSP ✔ Configurado
X-Frame-Options ⚠ No configurado
X-Content-Type-Options ✔ nosniff
Política de Referrer strict-origin-when-cross-origin
Política de Permisos ✔ Configurado
HTTP/2 ⚠ HTTP/1.1
Comprobación SEO
Título 403 Forbidden
Tecnologías Detectadas
| Tecnología | Google Analytics Apache PHP |
Tecnología Google Analytics Apache PHP
Cabeceras HTTP
| Date | Tue, 21 Jul 2026 13:39:09 GMT |
| Server | Apache |
| Content-Security-Policy-Report-Only | default-src 'self' https:; script-src 'self' https:; style-src 'self' https:; img-src 'self' data: https: blob:; font-src 'self' data: https:; connect-src 'self' https:; media-src 'self' https:; object-src 'none'; frame-src 'self' https:; frame-ancestors 'self'; base-uri 'self'; form-action 'self' https:; upgrade-insecure-requests; report-uri /csp-violations.php |
| X-Content-Type-Options | nosniff |
| X-XSS-Protection | 1; mode=block |
| Strict-Transport-Security | max-age=31536000; includeSubDomains; preload |
| Referrer-Policy | strict-origin-when-cross-origin |
| Permissions-Policy | geolocation=(), microphone=(), camera=(), payment=() |
| Content-Security-Policy | default-src 'self' https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: https: blob:; font-src 'self' data: https:; connect-src 'self' https: wss:; media-src 'self' https: blob:; object-src 'none'; frame-src 'self' https: blob:; frame-ancestors 'self'; base-uri 'self'; form-action 'self' https:; upgrade-insecure-requests |
| Content-Length | 199 |
| Content-Type | text/html; charset=iso-8859-1 |
Date Tue, 21 Jul 2026 13:39:09 GMT
Server Apache
Content-Security-Policy-Report-Only default-src 'self' https:; script-src 'self' https:; style-src 'self' https:; img-src 'self' data: https: blob:; font-src 'self' data: https:; connect-src 'self' https:; media-src 'self' https:; object-src 'none'; frame-src 'self' https:; frame-ancestors 'self'; base-uri 'self'; form-action 'self' https:; upgrade-insecure-requests; report-uri /csp-violations.php
X-Content-Type-Options nosniff
X-XSS-Protection 1; mode=block
Strict-Transport-Security max-age=31536000; includeSubDomains; preload
Referrer-Policy strict-origin-when-cross-origin
Permissions-Policy geolocation=(), microphone=(), camera=(), payment=()
Content-Security-Policy default-src 'self' https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: https: blob:; font-src 'self' data: https:; connect-src 'self' https: wss:; media-src 'self' https: blob:; object-src 'none'; frame-src 'self' https: blob:; frame-ancestors 'self'; base-uri 'self'; form-action 'self' https:; upgrade-insecure-requests
Content-Length 199
Content-Type text/html; charset=iso-8859-1