Open
Cached
·
just now
25
Headers
Detected Technologies from Headers
PayPal
AWS API Gateway
AWS CloudFront
YouTube
Google AdSense
Google Tag Manager
Azure Blob Storage
Envoy
Google DoubleClick
Google Analytics
Microsoft Advertising
Loggly
Google Static File Front End
LaunchDarkly
Next.js
Google API JS Client
Google Fonts
Hotjar
LinkedIn
LiveChat
unpkg
Google Search
Facebook
Amazon S3
OneTrust
Salesforce Sites
Storyblok
AWS
jQuery
Salesforce Pardot
Taboola
Vimeo
Sentry
Google Cloud
HTTP Security Headers
Status
Strict-Transport-Security
Excellent
max-age=31536000; includeSubDomains; preload
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Missing
Not configured
Recommendations
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
Vary
Accept-Encoding
connection: close vary: Accept-Encoding
Caching Headers
Cache-Control
private, no-cache, no-store, max-age=0, must-revalidate
Etag
"9llwrl3i162p65"
cache-control: private, no-cache, no-store, max-age=0, must-revalidate etag: "9llwrl3i162p65"
Content Headers
Content-Length
126549
Content-Type
text/html; charset=utf-8
content-length: 126549 content-type: text/html; charset=utf-8
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Date
Sat, 09 May 2026 16:45:28 GMT
Req-Id
ad785edf-7005-4d23-a97d-2dde92c1eeae
X-Dns-Prefetch-Control
off
X-Download-Options
noopen
X-Permitted-Cross-Domain-Policies
none
date: Sat, 09 May 2026 16:45:28 GMT req-id: ad785edf-7005-4d23-a97d-2dde92c1eeae via: 1.1 aadad266be53162e069ead52871dac74.cloudfront.net (CloudFront) x-amz-cf-id: jXeIvBgXERbM2i-FrvTWrMTR-PSlGNKMO6ATDekMakj0amC6lLTi6g== x-amz-cf-pop: IAD61-P4 x-cache: Miss from cloudfront x-dns-prefetch-control: off x-download-options: noopen x-envoy-upstream-service-time: 50 x-permitted-cross-domain-policies: none
Recommendations
Enable compression (gzip/brotli) to improve performance
Consider removing X-Powered-By header to hide server technology