Open
Cached
·
2h ago
22
Headers
Detected Technologies from Headers
AWS CloudFront
Auth0
Google Tag Manager
Bugsnag
Google reCAPTCHA
Amplitude
Fullstory
WordPress
Google Analytics
Pusher
Segment
Datadog
Google Static File Front End
LaunchDarkly
Calendly
Wistia
Zendesk
Stripe
Slack
Lottie Player
Google Search
Amazon S3
Heap
AWS
jQuery
Split.io
Active incidents
Vimeo
PostHog
Intercom
YouTube
Sentry
Google Cloud
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=5184000; includeSubdomains; preload
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Present
same-origin
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
connection: close
Caching Headers
Age
36704
Cache-Control
no-cache, no-store, must-revalidate
Etag
"9eeb4e4d2dd78df69e63fd4cbd3ccf90"
Last-Modified
Tue, 05 May 2026 13:52:22 GMT
age: 36704 cache-control: no-cache, no-store, must-revalidate etag: "9eeb4e4d2dd78df69e63fd4cbd3ccf90" last-modified: Tue, 05 May 2026 13:52:22 GMT
Content Headers
Content-Length
1555
Content-Type
text/html
content-length: 1555 content-type: text/html
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Date
Tue, 05 May 2026 13:53:17 GMT
X-Download-Options
noopen
X-Permitted-Cross-Domain-Policies
none
date: Tue, 05 May 2026 13:53:17 GMT via: 1.1 aaf016fef66eecea8770da00a4c0e9d6.cloudfront.net (CloudFront) x-amz-cf-id: CUHOpWRSlA6jehHnk6u76RPG9KN44iGScLXFjZOjsNavmeMS0FxaYQ== x-amz-cf-pop: IAD12-P4 x-amz-version-id: RiaZqXmrQlrKTcuSri_ZlmNe.OEUStmB x-cache: Hit from cloudfront x-download-options: noopen x-permitted-cross-domain-policies: none
Recommendations
Enable compression (gzip/brotli) to improve performance