Open
Cached
·
26m ago
21
Headers
Detected Technologies from Headers
AWS CloudFront
Algolia
Arcade
ClearBit
Firebase
Google Analytics
Google API JS Client
Google Cloud Functions
Google Cloud Storage
Google DoubleClick
Google Fonts
Google Hosted Libraries
Google Static File Front End
Google Tag Manager
HubSpot
HubSpot Analytics
HubSpot Forms
Intercom
jsDelivr
LinkedIn
Liveblocks
Mux
Pexels
PostHog
Sentry
Stripe
Vercel
Google Cloud
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=63072000
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Accept-Ranges
bytes
Connection
close
accept-ranges: bytes connection: close
Caching Headers
Age
770
Cache-Control
public, max-age=0, must-revalidate
Etag
"672917e30c43d763d9249d9f72a6dc6e"
Last-Modified
Tue, 06 Oct 2026 22:23:39 GMT
age: 770 cache-control: public, max-age=0, must-revalidate etag: "672917e30c43d763d9249d9f72a6dc6e" last-modified: Tue, 06 Oct 2026 22:23:39 GMT
Content Headers
Content-Disposition
inline; filename="auth"
Content-Length
5116
Content-Type
text/html; charset=utf-8
content-disposition: inline; filename="auth" content-length: 5116 content-type: text/html; charset=utf-8
CORS Headers
Access-Control-Allow-Origin
*
access-control-allow-origin: *
Cookies Headers
Other Headers
Date
Tue, 06 Oct 2026 22:36:29 GMT
X-Dns-Prefetch-Control
on
X-Matched-Path
/auth
date: Tue, 06 Oct 2026 22:36:29 GMT x-dns-prefetch-control: on x-matched-path: /auth x-vercel-cache: HIT x-vercel-id: iad1::td5sl-1791326189970-e6c34137db43
Recommendations
Enable compression (gzip/brotli) to improve performance