Open
Cached
·
just now
17
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000
Content-Security-Policy
Basic
connect-src; default-src; font-src; +7 more
connect-src 'self' wss://pod-29-sunco-ws.zendesk.com https://ekr.zdassets.com https://o37403.ingest.sentry.io https://ometria.zendesk.com https://zendesk-eu.my.sentry.io wss://api.appcues.net wss://realtime.ometria.com wss://widget-mediator.zopim.com https://widget-mediator.zopim.com https://id.zopim.com https://api.appcues.net https://fast.appcues.com https://mt.auryc.com *.auryc.com https://docs.google.com https://maps.googleapis.com https://graph.facebook.com;default-src 'self' https://fonts.googleapis.com https://fast.appcues.com https://docs.google.com;font-src 'self' data: https://fonts.gstatic.com https://fast.appcues.com *.auryc.com;frame-src 'self' https://embedded.tray.io https://qsptd9t61ych.statuspage.io https://www.google.com https://docs.google.com https://visual-editor.ometria.email;img-src 'self' data: https: blob:;media-src https://static.zdassets.com data:;script-src 'self' 'unsafe-eval' 'unsafe-inline' https://fast.appcues.com https://qsptd9t61ych.statuspage.io https://static.zdassets.com https://d3tcta4is3p1kw.cloudfront.net https://widget-mediator.zopim.com https://www.google.com https://www.gstatic.com https://maps.googleapis.com;style-src 'self' 'unsafe-inline' https://fast.appcues.com https://fonts.googleapis.com;worker-src blob:; report-uri https://o37403.ingest.sentry.io/api/86707/security/?sentry_key=b7f5b3d8efd34103a7e407510be4bc52
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Consider adding Permissions-Policy to control browser features
Performance Headers
2 headers
Connection
Performance
close
Transfer-Encoding
Performance
chunked
Caching Headers
2 headers
Cache-Control
Caching
no-cache
Pragma
Caching
no-cache
Content Headers
1 headers
Content-Type
Content
text/html; charset=UTF-8
Server Headers
1 headers
Server
Server
nginx
CORS Headers
1 headers
Access-Control-Allow-Origin
Cors
https://app.ometria.com
Cookies Headers
1 headers
Set-Cookie
Cookies
PHPSESSID=5gnl2f6qoutrd6269a1ecu5u3g; path=/; secure; HttpOnly
Other Headers
3 headers
Date
Other
Sat, 06 Dec 2025 03:44:00 GMT
X-Permitted-Cross-Domain-Policies
Other
none
X-Request-Id
Other
cd511232-d255-11f0-91be-423d29c66833
Recommendations
Enable compression (gzip/brotli) to improve performance
Analysis completed in 1519ms