26 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31536000; includeSubdomains; preload
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Consider adding Permissions-Policy to control browser features

Performance Headers

3 headers
Accept-Ranges
Performance
bytes
Connection
Performance
keep-alive
Vary
Performance
Accept-Encoding

Caching Headers

2 headers
Cache-Control
Caching
max-age=0, private, must-revalidate
Etag
Caching
W/"e67c1c06566b97001695e528ab31c6ce"

Content Headers

2 headers
Content-Length
Content
36279
Content-Type
Content
text/html; charset=utf-8

Server Headers

2 headers
Server
Server
CDN77-Turbo
X-Runtime
Server
0.002673

CORS Headers

0 headers
No CORS headers found

Cookies Headers

0 headers
No cookies headers found

Other Headers

12 headers
Date
Other
Fri, 07 Nov 2025 03:14:02 GMT
Link
Other
<https://assets0.headwayapp.co/hello-assets/nice-to-meet-you/application-4URqAQRM.js>; rel=modulepreload; as=script; crossorigin=anonymous; nopush,<https://assets0.headwayapp.co/hello-assets/nice-to-meet-you/application-D88Lqnp0.css>; rel=preload; as=style; nopush,<https://assets0.headwayapp.co/hello-assets/nice-to-meet-you/tailwind-Dbfp1gJ_.css>; rel=preload; as=style; nopush,<https://assets0.headwayapp.co/hello-assets/nice-to-meet-you/responsiveVideo-qk0CNcx5.css>; rel=preload; as=style; nopush
Via
Other
1.1 97a1bb4fb9aff82a97dbf758ce602258.cloudfront.net (CloudFront)
X-77-Cache
Other
MISS
X-77-Nzt
Other
EggBbT1bxAFBCAFZu7EYASE
X-77-Nzt-Ray
Other
bff7651d285b651bfa630d6992054901
X-77-Pop
Other
ashburnUSVA
X-Amz-Cf-Id
Other
9JRcrFtcaX1sE9y3UWR0BqAsF-KP65BMnObEiIYPHkplRABQdWJ7KQ==
X-Amz-Cf-Pop
Other
YUL62-P2
X-Hello
Other
headway
X-Permitted-Cross-Domain-Policies
Other
none
X-Request-Id
Other
2b48213e-b3f9-4094-aa35-51f9299bec7a

Recommendations

Enable compression (gzip/brotli) to improve performance

Analysis completed in 136ms