Información Técnica
| Código de estado HTTP | 200 |
| Versión HTTP | HTTP/1.1 |
| HTTPS | ✔ Disponible |
| Dirección IP | 23.39.245.87 |
| Compresión | gzip |
|
ℹ 🔵 Falta X-Frame-Options | El sitio puede ser incrustado en iframes por terceros (riesgo de clickjacking). |
Código de estado HTTP 200
Versión HTTP HTTP/1.1
HTTPS ✔ Disponible
Dirección IP 23.39.245.87
Compresión gzip
ℹ 🔵 Falta X-Frame-Options El sitio puede ser incrustado en iframes por terceros (riesgo de clickjacking).
Cadena de Redirecciones
| # | URL | Código de estado HTTP | Estado |
| 1 | https://subway.com:443 | 302 | HTTP/2 302 |
| 2 | https://subwayfrance.fr/ | 200 | HTTP/2 200 |
#1 URL https://subway.com:443
Código de estado HTTP 302
Estado HTTP/2 302
#2 URL https://subwayfrance.fr/
Código de estado HTTP 200
Estado HTTP/2 200
Rendimiento
| Resolución DNS | 22.9 ms |
| Conexión TCP | 25 ms |
| Negociación TLS | 4.1 ms |
| Tiempo hasta el primer byte (TTFB) | 269.9 ms |
| Descarga de contenido | 2.1 ms |
| Tiempo total de respuesta | 271.9 ms |
Resolución DNS 22.9 ms
Conexión TCP 25 ms
Negociación TLS 4.1 ms
Tiempo hasta el primer byte (TTFB) 269.9 ms
Descarga de contenido 2.1 ms
Tiempo total de respuesta 271.9 ms
Seguridad
| HTTPS | ✔ Activado |
| HSTS | ✔ max-age=31536000; includeSubDomains; preload |
| CSP | ✔ Configurado |
| X-Frame-Options | ⚠ No configurado |
| X-Content-Type-Options | ✔ nosniff |
| Política de Referrer | no-referrer |
| Política de Permisos | ✔ Configurado |
| HTTP/2 | ⚠ HTTP/1.1 |
HTTPS ✔ Activado
HSTS ✔ max-age=31536000; includeSubDomains; preload
CSP ✔ Configurado
X-Frame-Options ⚠ No configurado
X-Content-Type-Options ✔ nosniff
Política de Referrer no-referrer
Política de Permisos ✔ Configurado
HTTP/2 ⚠ HTTP/1.1
Comprobación SEO
| Título | Home | Subway France |
Título Home | Subway France
Tecnologías Detectadas
| Tecnología | React Google Analytics Google Tag Manager Next.js |
Tecnología React Google Analytics Google Tag Manager Next.js
Cabeceras HTTP
| Content-security-policy
| default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://www.googletagmanager.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://www.instagram.com; connect-src 'self' https://www.googletagmanager.com https://www.google-analytics.com https://consent.cookiebot.com https://consentcdn.cookiebot.com; style-src 'self' 'unsafe-inline'; img-src https: 'self' blob: data:; font-src 'self'; frame-src https://www.googletagmanager.com https://consentcdn.cookiebot.com https://www.instagram.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' https://tagassistant.google.com; upgrade-insecure-requests; |
| X-permitted-cross-domain-policies
| none |
| Referrer-policy
| no-referrer |
| X-content-type-options
| nosniff |
| Permissions-policy
| autoplay=() |
| Strict-transport-security
| max-age=31536000; includeSubDomains; preload |
| X-powered-by
| Next.js |
| Cache-control
| private, no-cache, no-store, max-age=0, must-revalidate |
| Etag
| "14bqrssituf467z" |
| Content-type
| text/html; charset=utf-8 |
| Vary
| Accept-Encoding |
| Content-encoding
| gzip |
| Date
| Tue, 21 Jul 2026 11:26:06 GMT |
Meta Tags
| Viewport | width=device-width |
| Next-head-count | 13 |
Content-security-policy default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://www.googletagmanager.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://www.instagram.com; connect-src 'self' https://www.googletagmanager.com https://www.google-analytics.com https://consent.cookiebot.com https://consentcdn.cookiebot.com; style-src 'self' 'unsafe-inline'; img-src https: 'self' blob: data:; font-src 'self'; frame-src https://www.googletagmanager.com https://consentcdn.cookiebot.com https://www.instagram.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' https://tagassistant.google.com; upgrade-insecure-requests;
X-permitted-cross-domain-policies none
Referrer-policy no-referrer
X-content-type-options nosniff
Permissions-policy autoplay=()
Strict-transport-security max-age=31536000; includeSubDomains; preload
X-powered-by Next.js
Cache-control private, no-cache, no-store, max-age=0, must-revalidate
Etag "14bqrssituf467z"
Content-type text/html; charset=utf-8
Vary Accept-Encoding
Content-encoding gzip
Date Tue, 21 Jul 2026 11:26:06 GMT