Open
Cached
·
just now
21
Headers
Detected Technologies from Headers
Cloudflare CSP Monitoring
YouTube
Google AdSense
Google Maps
Google Tag Manager
Fullstory
Reddit
Tenor
HubSpot Forms
OptinMonster
Google DoubleClick
Google Analytics
Microsoft Advertising
Yoast
Cloudflare CDN
Google Static File Front End
Calendly
Google Fonts
Cloudflare Web Analytics
Hotjar
LinkedIn
HubSpot Analytics
Cloudflare Access
unpkg
Google Search
Facebook
CookieYes
PHP
Cloudflare CDNJS
Convert
HubSpot
Intercom
Sentry
jsDelivr
Google Cloud
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=7776000; includeSubDomains; preload
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
no-referrer-when-downgrade
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
Transfer-Encoding
chunked
Vary
Accept-Encoding
connection: close transfer-encoding: chunked vary: Accept-Encoding
Caching Headers
Cache-Control
max-age=0
Expires
Tue, 28 Apr 2026 11:29:47 GMT
Last-Modified
Tue, 28 Apr 2026 07:30:24 GMT
cache-control: max-age=0 expires: Tue, 28 Apr 2026 11:29:47 GMT last-modified: Tue, 28 Apr 2026 07:30:24 GMT
Content Headers
Content-Type
text/html; charset=UTF-8
content-type: text/html; charset=UTF-8
Server Headers
server: cloudflare x-powered-by: PHP/8.4.20
CORS Headers
Access-Control-Allow-Headers
baggage, sentry-trace
Access-Control-Allow-Methods
OPTION
access-control-allow-headers: baggage, sentry-trace access-control-allow-methods: OPTION
Cookies Headers
Other Headers
Alt-Svc
h3=":443"; ma=86400
Cf-Apo-Via
origin,miss
Date
Tue, 28 Apr 2026 11:29:47 GMT
Report-To
Other
Group
cf-wuiyjtavvxcgymrn
max-age: 1d
alt-svc: h3=":443"; ma=86400
cf-apo-via: origin,miss
cf-cache-status: MISS
cf-ray: 9f35bb2feaba1625-IAD
date: Tue, 28 Apr 2026 11:29:47 GMT
report-to: {"group":"cf-wuiyjtavvxcgymrn","max_age":86400,"endpoints":[{"url":"https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=50PpiIAih3awBdzTjOuHmHYvN3x.Fd6wps09jsQ0nS0-1777375787.5060098-1.0.1.1-jbfmc4ZouF6Ms3DPucrv3Vgl.qVJJVRVd0KI4BUeM3DMxTwqfUeWcf3CPqESOwaKxcMVqnXg08ezPIk_m5qcPC8hcehNVXa3Q2xwGwBk.k2hYIa1eNFwodjePYqbA9WgQ0WrXy1qnPdgad6acDFX5BACilOLIPZtBKYJlPtxtfE0WqEqDxC5uWHlvxGtpTzoKk_gluYnvCTdpB2.1Y0Blw"}]}
Recommendations
Enable compression (gzip/brotli) to improve performance
Consider removing X-Powered-By header to hide server technology