Open
Cached
·
just now
25
Headers
Detected Technologies from Headers
AWS CloudFront
YouTube
Google Maps
IPinfo
Google Tag Manager
Bing
Google reCAPTCHA
Google Cloud Run
Reddit
Liveramp
Google DoubleClick
Google Analytics
Crazy Egg
New Relic
Cloudflare CDN
Google Static File Front End
Unsplash
Google API JS Client
Google Fonts
Clickagy
Twitter
Bunny Fonts
Cloudflare Web Analytics
Klaviyo
unpkg
Google Search
Facebook
Shopify
TikTok
AWS
Vimeo
Microsoft Clarity
Font Awesome
Google Cloud
Google Cloud Storage
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
Transfer-Encoding
chunked
Vary
Accept-Encoding, Origin,Host
connection: close transfer-encoding: chunked vary: Accept-Encoding, Origin,Host
Caching Headers
Cache-Control
no-store, no-cache, must-revalidate, max-age=0
Expires
-1
Pragma
no-cache
cache-control: no-store, no-cache, must-revalidate, max-age=0 expires: -1 pragma: no-cache
Content Headers
Content-Type
text/html; charset=UTF-8
content-type: text/html; charset=UTF-8
Server Headers
server: cloudflare x-powered-by: Magic
CORS Headers
Access-Control-Allow-Credentials
true
Access-Control-Allow-Headers
Accept,Authorization,Cache-Control,Content-Type,DNT,If-Modified-Since,Keep-Alive,Origin,User-Agent,X-Requested-With,Range
Access-Control-Allow-Methods
GET, POST, PUT, DELETE, OPTIONS
Access-Control-Allow-Origin
https://www.ammunitiondepot.com
Access-Control-Expose-Headers
Authorization
access-control-allow-credentials: true access-control-allow-headers: Accept,Authorization,Cache-Control,Content-Type,DNT,If-Modified-Since,Keep-Alive,Origin,User-Agent,X-Requested-With,Range access-control-allow-methods: GET, POST, PUT, DELETE, OPTIONS access-control-allow-origin: https://www.ammunitiondepot.com access-control-expose-headers: Authorization
Cookies Headers
Other Headers
Alt-Svc
h3=":443"; ma=86400
Date
Wed, 08 Apr 2026 07:07:34 GMT
Server-Timing
cfCacheStatus;desc="DYNAMIC", cfEdge;dur=12,cfOrigin;dur=5
X-Built-With
Hyva Themes
alt-svc: h3=":443"; ma=86400 cf-cache-status: DYNAMIC cf-ray: 9e8f6f93dd890834-IAD date: Wed, 08 Apr 2026 07:07:34 GMT server-timing: cfCacheStatus;desc="DYNAMIC", cfEdge;dur=12,cfOrigin;dur=5 x-built-with: Hyva Themes
Recommendations
Enable compression (gzip/brotli) to improve performance
Consider removing X-Powered-By header to hide server technology