Open
Cached
·
1h ago
15
Headers
Detected Technologies from Headers
AWS CloudFront
AppNexus (Xandr)
Active incidents
Bing
BootstrapCDN
Cloudflare CDN
Cloudflare Turnstile
Cloudflare Web Analytics
Facebook
Google AdSense
Google Analytics
Google API JS Client
Google DoubleClick
Google Fonts
Google Hosted Libraries
Google Optimize
Google Search
Google Static File Front End
Google Tag Manager
jQuery
Microsoft Clarity
OneTrust
Uberall
Yoast
YouTube
Google Cloud
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
Transfer-Encoding
chunked
Vary
Accept-Encoding,User-Agent
connection: close transfer-encoding: chunked vary: Accept-Encoding,User-Agent
Caching Headers
Cache-Control
no-cache, private
cache-control: no-cache, private
Content Headers
Content-Type
text/html; charset=UTF-8
content-type: text/html; charset=UTF-8
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Alt-Svc
h3=":443"; ma=86400
Date
Wed, 06 May 2026 09:30:33 GMT
Server-Timing
cfCacheStatus;desc="DYNAMIC", cfEdge;dur=15,cfOrigin;dur=702
alt-svc: h3=":443"; ma=86400 cf-cache-status: DYNAMIC cf-ray: 9f76f7812e5d2d0b-IAD date: Wed, 06 May 2026 09:30:33 GMT server-timing: cfCacheStatus;desc="DYNAMIC", cfEdge;dur=15,cfOrigin;dur=702
Recommendations
Enable compression (gzip/brotli) to improve performance