Technical Information
| HTTP Status Code | 200 |
| HTTP Version | HTTP/1.1 |
| HTTPS | ✔ Available |
| IP Address | 99.86.109.58 |
| Server Software | cloudflare |
| CDN | Cloudflare |
| Compression | gzip |
|
🔒 🟡 Mixed Content (2 HTTP resources) | The page is served over HTTPS but loads 2 resource(s) over HTTP. This may be blocked in modern browsers. |
|
🕐 🟡 Slow Response (1112 ms) | Response time exceeds 1 second. Consider optimizing the server or using caching. |
|
ℹ 🔵 Missing Content Security Policy | CSP is not configured. It helps prevent XSS attacks and content injection. |
HTTP Status Code 200
HTTP Version HTTP/1.1
HTTPS ✔ Available
IP Address 99.86.109.58
Server Software cloudflare
CDN Cloudflare
Compression gzip
🔒 🟡 Mixed Content (2 HTTP resources) The page is served over HTTPS but loads 2 resource(s) over HTTP. This may be blocked in modern browsers.
🕐 🟡 Slow Response (1112 ms) Response time exceeds 1 second. Consider optimizing the server or using caching.
ℹ 🔵 Missing Content Security Policy CSP is not configured. It helps prevent XSS attacks and content injection.
Redirect Chain
| # | URL | HTTP Status Code | Status |
| 1 | https://ycombinator.com:443 | 301 | HTTP/1.1 301 Moved Permanently |
| 2 | https://www.ycombinator.com/ | 200 | HTTP/2 200 |
#1 URL https://ycombinator.com:443
HTTP Status Code 301
Status HTTP/1.1 301 Moved Permanently
#2 URL https://www.ycombinator.com/
HTTP Status Code 200
Status HTTP/2 200
Performance
| DNS Lookup | 21.7 ms |
| TCP Connect | 23.4 ms |
| TLS Handshake | 13.3 ms |
| Time To First Byte (TTFB) | 957.8 ms |
| Content Download | 154.2 ms |
| Total Response Time | 1112 ms |
DNS Lookup 21.7 ms
TCP Connect 23.4 ms
TLS Handshake 13.3 ms
Time To First Byte (TTFB) 957.8 ms
Content Download 154.2 ms
Total Response Time 1112 ms
Security
| HTTPS | ✔ Enabled |
| HSTS | ✔ max-age=63072000; includeSubDomains |
| CSP | ⚠ Not configured |
| X-Frame-Options | ✔ SAMEORIGIN |
| X-Content-Type-Options | ✔ nosniff |
| Referrer Policy | strict-origin-when-cross-origin |
| HTTP/2 | ⚠ HTTP/1.1 |
HTTPS ✔ Enabled
HSTS ✔ max-age=63072000; includeSubDomains
CSP ⚠ Not configured
X-Frame-Options ✔ SAMEORIGIN
X-Content-Type-Options ✔ nosniff
Referrer Policy strict-origin-when-cross-origin
HTTP/2 ⚠ HTTP/1.1
SEO Quick Check
Title Y Combinator
Detected Technologies
| Technology | React Google Analytics Cloudflare |
Technology React Google Analytics Cloudflare
HTTP Headers
| Date
| Mon, 31 Aug 2026 16:34:23 GMT |
| Content-type
| text/html; charset=utf-8 |
| X-frame-options
| SAMEORIGIN |
| X-xss-protection
| 1; mode=block |
| X-content-type-options
| nosniff |
| X-download-options
| noopen |
| X-permitted-cross-domain-policies
| none |
| Referrer-policy
| strict-origin-when-cross-origin |
| Cross-origin-opener-policy
| same-origin |
| Vary
| X-Inertia,Accept-Encoding |
| Link
| ; rel=preload; as=style; nopush,; rel=modulepreload; as=script; crossorigin=; nopush,; rel=preload; as=style; crossorigin=; nopush,; rel=preload; as=style; crossorigin=; nopush,; rel=preload; as=style; crossorigin=; nopush,; rel=preload; as=style; crossorigin=; nopush,; rel=preload; as=style; crossorigin=; nopush,; rel=preload; as=style; crossorigin=; nopush |
| Etag
| W/"edc04c5847c9d7847193e03fa3e31699" |
| Cache-control
| max-age=0, private, must-revalidate |
| Content-security-policy-report-only
| script-src 'self' https: https://www.google-analytics.com https://cdn.amplitude.com 'unsafe-eval' 'unsafe-inline' data: 'nonce-4pOZOaqa/UUzNnWQbFyL9Q=='; worker-src blob: data:; report-uri https://us.sentry.io/api/4506690010480640/security/?sentry_key=aab2498373841041d6b48d721aefbdc1&sentry_environment=production&sentry_release=70788c303b20469a892208f50be7ecedf71e5ea5 |
| Set-cookie
| _bf_session_key=i4jMu%2FPpZeXJmmC5BLd9L4525%2B4YECjesbw1bJsD%2BL4f%2BhpMCkLr%2FPRRXpXKnTvv%2BGqgrMG89pBzbbMBFgVxE%2B4M8x9stUwMX5WAYmN%2Bkc01TpHzbFcAYRnfJUP6VuencXkLNgkIHOJmz%2FFs2oQNGkCcUeseTkOoF3ZESvNRao7rAP4f4EsIO4%2BdeeD13HIAbpMgrtoReCVllRng%2FuyWM5eiJ9%2BJJhdtYpQ47uOaCz019sdNO8V9reQT%2BoPwg4As2%2BZ146arajt4jWH33oOs2C%2BnCSRA57w%3D--pRd%2BUkyAe11CkgNy--VIhp0E%2FzQoObgxkWSGnAVg%3D%3D; path=/; secure; httponly; samesite=lax |
| X-request-id
| 782e353c-64a8-418d-89a5-c2021cce55aa |
| X-runtime
| 0.082201 |
| Strict-transport-security
| max-age=63072000; includeSubDomains |
| Content-encoding
| gzip |
| Cf-cache-status
| DYNAMIC |
| Server
| cloudflare |
| Cf-ray
| a33d713acb522a4d-CDG |
Meta Tags
| Csrf-param | authenticity_token |
| Csrf-token | wSF6E9fiCYq7JZYKPN1Z2NgyyV6hMgQbyK4ZeJTMrjnr4VQcurV_gF7eDuU8nDHQwGhKwSo5JDnEJWy6HYopSw |
Date Mon, 31 Aug 2026 16:34:23 GMT
Content-type text/html; charset=utf-8
X-frame-options SAMEORIGIN
X-xss-protection 1; mode=block
X-content-type-options nosniff
X-download-options noopen
X-permitted-cross-domain-policies none
Referrer-policy strict-origin-when-cross-origin
Cross-origin-opener-policy same-origin
Vary X-Inertia,Accept-Encoding
Link ; rel=preload; as=style; nopush,; rel=modulepreload; as=script; crossorigin=; nopush,; rel=preload; as=style; crossorigin=; nopush,; rel=preload; as=style; crossorigin=; nopush,; rel=preload; as=style; crossorigin=; nopush,; rel=preload; as=style; crossorigin=; nopush,; rel=preload; as=style; crossorigin=; nopush,; rel=preload; as=style; crossorigin=; nopush
Etag W/"edc04c5847c9d7847193e03fa3e31699"
Cache-control max-age=0, private, must-revalidate
Content-security-policy-report-only script-src 'self' https: https://www.google-analytics.com https://cdn.amplitude.com 'unsafe-eval' 'unsafe-inline' data: 'nonce-4pOZOaqa/UUzNnWQbFyL9Q=='; worker-src blob: data:; report-uri https://us.sentry.io/api/4506690010480640/security/?sentry_key=aab2498373841041d6b48d721aefbdc1&sentry_environment=production&sentry_release=70788c303b20469a892208f50be7ecedf71e5ea5
Set-cookie _bf_session_key=i4jMu%2FPpZeXJmmC5BLd9L4525%2B4YECjesbw1bJsD%2BL4f%2BhpMCkLr%2FPRRXpXKnTvv%2BGqgrMG89pBzbbMBFgVxE%2B4M8x9stUwMX5WAYmN%2Bkc01TpHzbFcAYRnfJUP6VuencXkLNgkIHOJmz%2FFs2oQNGkCcUeseTkOoF3ZESvNRao7rAP4f4EsIO4%2BdeeD13HIAbpMgrtoReCVllRng%2FuyWM5eiJ9%2BJJhdtYpQ47uOaCz019sdNO8V9reQT%2BoPwg4As2%2BZ146arajt4jWH33oOs2C%2BnCSRA57w%3D--pRd%2BUkyAe11CkgNy--VIhp0E%2FzQoObgxkWSGnAVg%3D%3D; path=/; secure; httponly; samesite=lax
X-request-id 782e353c-64a8-418d-89a5-c2021cce55aa
X-runtime 0.082201
Strict-transport-security max-age=63072000; includeSubDomains
Content-encoding gzip
Cf-cache-status DYNAMIC
Server cloudflare
Cf-ray a33d713acb522a4d-CDG