Open
Cached
·
just now
19
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=15552000
Content-Security-Policy
Weak
frame-ancestors; report-uri
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Significantly strengthen CSP directives
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
3 headers
Connection
Performance
close
Transfer-Encoding
Performance
chunked
Vary
Performance
Accept-Encoding
Caching Headers
3 headers
Cache-Control
Caching
max-age=0, must-revalidate, no-cache, no-store
Expires
Caching
Sun, 29 Dec 2024 09:08:55 GMT
Pragma
Caching
no-cache
Content Headers
1 headers
Content-Type
Content
text/html; charset=UTF-8
Server Headers
1 headers
Server
Server
cloudflare
CORS Headers
0 headers
No CORS headers found
Cookies Headers
1 headers
Set-Cookie
Cookies
wcid=Ab65i0rdFXsxAAAB; Path=/; Domain=127.0.0.1; Max-Age=31536000; HttpOnly; SameSite=Lax; Secure
Other Headers
5 headers
Cf-Cache-Status
Other
DYNAMIC
Cf-Ray
Other
9b5827d7fecd1972-IAD
Content-Security-Policy-Report-Only
Other
font-src *.googleapis.com *.gstatic.com 'self' data: fonts.gstatic.com *.cloudmaestro.com *.punchout2go.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.authorize.net *.punchout2go.com 'self' data: *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.certcapture.com *.punchout2go.com 'self' data: 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googletagmanager.com *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.certcapture.com *.doubleclick.net *.facebook.com events.blackthorn.io *.punchout2go.com *.weltpixel.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net data: *.gstatic.com *.googleapis.com *.certcapture.com maps.googleapis.com www.googletagmanager.com www.google.com *.cloudmaestro.com *.doubleclick.net *.scene7.com *.bakerdist.com bam.nr-data.net *.punchout2go.com https://firebasestorage.googleapis.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.certcapture.com cdnjs.cloudflare.com cdn.jsdelivr.net static.cloudflareinsights.com unpkg.com *.onetrust.com cdn.cookielaw.org maps.googleapis.com *.punchout2go.com *.tradecentric.com cdn.polyfill.io *.cloudmaestro.com js-agent.newrelic.com bam.nr-data.net *.authorize.net *.bakerdist.com static.zdassets.com cdn.rudderlabs.com events.blackthorn.io *.avada.io *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com cdnjs.cloudflare.com *.cloudmaestro.com *.punchout2go.com *.tradecentric.com *.bakerdist.com *.fontawesome.com https://fonts.bunny.net *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src *.punchout2go.com *.tradecentric.com *.buyerquest.net bam.nr-data.net 'self' 'unsafe-inline'; media-src *.adobe.com static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com *.newrelic.com *.nr-data.net vimeo.com *.googleapis.com *.certcapture.com *.bakerdist.com bam.nr-data.net *.authorize.net cdn.cookielaw.org *.scene7.com lkx760tcl7.execute-api.us-east-1.amazonaws.com www.facebook.com wss://widget-mediator.zopim.com static.cloudflareinsights.com bakerdist.zendesk.com ekr.zdassets.com bkuatdmbogssdi.dataplane.rudderstack.com bkprodukgnhabu.dataplane.rudderstack.com api.rudderstack.com geolocation.onetrust.com privacyportal.onetrust.com boltgw-uat.cardconnect.com:* boltgw.cardconnect.com:* *.punchout2go.com https://get.geojs.io *.avada.io *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline';
Date
Other
Mon, 29 Dec 2025 09:08:56 GMT
X-Magento-Tags
Other
FPC
Recommendations
Enable compression (gzip/brotli) to improve performance
Analysis completed in 630ms