Open
Cached
·
just now
21
Headers
Detected Technologies from Headers
YouTube
Acquia Optimize
Active incidents
Ahrefs
AWS
Azure Blob Storage
Facebook
Freshworks
Google AdSense
Google Analytics
Google DoubleClick
Google Fonts
Google Search
Google Static File Front End
Google Tag Manager
Hotjar
HubSpot
HubSpot Analytics
HubSpot Forms
Issuu
Leadfeeder
LinkedIn
Next.js
OneTrust
Sanity
Vercel
Vimeo
Google Cloud
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=63072000
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Present
origin-when-cross-origin
Permissions-Policy
Present
camera=(), microphone=(), geolocation=()
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
Performance Headers
Connection
close
Vary
rsc, next-router-state-tree, next-router-prefetch, next-router-segment-prefetch
connection: close vary: rsc, next-router-state-tree, next-router-prefetch, next-router-segment-prefetch
Caching Headers
Age
323034
Cache-Control
public, max-age=0, must-revalidate
Etag
"urxhcqc32x488z"
age: 323034 cache-control: public, max-age=0, must-revalidate etag: "urxhcqc32x488z"
Content Headers
Content-Length
202997
Content-Type
text/html; charset=utf-8
content-length: 202997 content-type: text/html; charset=utf-8
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Date
Tue, 05 May 2026 12:34:43 GMT
X-Matched-Path
/default/en
X-Nextjs-Rewritten-Path
/default/en/
date: Tue, 05 May 2026 12:34:43 GMT x-matched-path: /default/en x-nextjs-prerender: 1 x-nextjs-rewritten-path: /default/en/ x-nextjs-stale-time: 300 x-vercel-cache: HIT x-vercel-id: iad1::iad1::sgmjp-1778307517884-566e5c9e8acb
Recommendations
Enable compression (gzip/brotli) to improve performance