Open
Cached
·
just now
22
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Excellent
max-age=63072000; includeSubDomains; preload
Content-Security-Policy
Good
script-src; style-src; img-src; +13 more
script-src 'nonce-Oexj5Mf70VqttINbQ6juag==' 'self' cdn.perkbox.dev cdn.perkbox.net cdn.perkbox.com *.marketo.com app.phrase.com phraseapp.com *.googleapis.com apis.google.com *.google-analytics.com *.googletagmanager.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ *.intercom.io *.intercomcdn.com *.mxpnl.com *.mixpanel.com *.chilipiper.com *.coview.com *.stripe.com *.fidel.uk *.asknice.ly *.vimeo.com *.adyen.com accounts.google.com *.checkout.com *.paypal.com *.paypalobjects.com 'sha256-3plJBhqO9pYy4GbXJtuQhM3g/yksi0RyVGpeDp0SRe0=' teams.microsoft.com *.zuora.com *.cloud.microsoft clarity.microsoft.com *.clarity.ms;style-src 'self' 'unsafe-inline' cdn.perkbox.dev cdn.perkbox.net cdn.perkbox.com *.marketo.com app.phrase.com phraseapp.com phrase.com *.chilipiper.com *.coview.com *.googleapis.com *.typekit.net *.stripe.com *.fidel.uk *.fontawesome.com accounts.google.com;img-src * blob: data: cdn.perkbox.dev cdn.perkbox.net cdn.perkbox.com js.intercomcdn.com static.intercomassets.com downloads.intercomcdn.com downloads.intercomcdn.eu downloads.au.intercomcdn.com uploads.intercomusercontent.com gifs.intercomcdn.com video-messages.intercomcdn.com messenger-apps.intercom.io messenger-apps.eu.intercom.io messenger-apps.au.intercom.io *.intercom-attachments-1.com *.intercom-attachments.eu *.au.intercom-attachments.com *.intercom-attachments-2.com *.intercom-attachments-3.com *.intercom-attachments-4.com *.intercom-attachments-5.com *.intercom-attachments-6.com *.intercom-attachments-7.com *.intercom-attachments-8.com *.intercom-attachments-9.com static.intercomassets.eu static.au.intercomassets.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/;connect-src * *.intercom.io *.intercomcdn.eu *.intercomcdn.com *.intercomcdn.com *.intercomusercontent.com;frame-src self * *.google.com *.adyen.com *.vimeo.com cdn.perkbox.com cdn.perkbox.net;media-src cdn.perkbox.net cdn.perkbox.com js.intercomcdn.com;form-action self * *.perkbox.dev *.perkbox.net *.perkbox.com *.localhost:* intercom.help *.intercom.io;worker-src 'self' blob: *.perkbox.net *.perkbox.com *.perkbox.dev;child-src 'self' intercom-sheets.com *.intercom-reporting.com *.youtube.com *.vimeo.com *.wistia.net;default-src 'self';base-uri 'self';font-src 'self' https: data:;frame-ancestors 'self';object-src 'none';script-src-attr 'none';upgrade-insecure-requests
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Present
origin,origin-when-cross-origin,strict-origin-when-cross-origin
Permissions-Policy
Missing
Not configured
Recommendations
- • Strengthen CSP by removing 'unsafe-eval'
- • Consider adding Permissions-Policy to control browser features
Performance Headers
1 headers
Connection
Performance
close
Caching Headers
4 headers
Cache-Control
Caching
no-store, no-cache, must-revalidate, proxy-revalidate
Etag
Caching
W/"780-px153HN/meZxZ1Jmg/WWz6B7Tmc"
Expires
Caching
0
Pragma
Caching
no-cache
Content Headers
2 headers
Content-Length
Content
1920
Content-Type
Content
text/html; charset=utf-8
Server Headers
0 headers
No server headers found
CORS Headers
0 headers
No CORS headers found
Cookies Headers
1 headers
Set-Cookie
Cookies
sid=s%3Abaiuz13k4Vvh0sS1rQrLauMk9RmLFqn3.rlDDBsa13YX9HsuYvvbMWuB%2Fj9u1flwgyN5ZTO3%2FYJc; Path=/; Expires=Wed, 01 Apr 2026 14:52:24 GMT; HttpOnly; Secure; SameSite=Lax
Other Headers
6 headers
Date
Other
Sat, 31 Jan 2026 14:52:24 GMT
Origin-Agent-Cluster
Other
?1
Surrogate-Control
Other
no-store
X-Dns-Prefetch-Control
Other
off
X-Download-Options
Other
noopen
X-Permitted-Cross-Domain-Policies
Other
none
Recommendations
Enable compression (gzip/brotli) to improve performance