Cached · just now
28 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Basic
default-src; script-src; object-src; +10 more Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Improve CSP by adding more specific directives and removing 'unsafe-inline'
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

Performance Headers

Accept-Ranges
Performance
bytes
Connection
Performance
close
Vary
Performance
Cookie, Accept-Encoding

Caching Headers

Age
Caching
76743
Cache-Control
Caching
max-age=2764800, public
Etag
Caching
W/"1778230804-gzip"
Expires
Caching
Sun, 19 Nov 1978 05:00:00 GMT
Last-Modified
Caching
Fri, 08 May 2026 09:00:04 GMT

Content Headers

Content-Language
Content
en
Content-Length
Content
104969
Content-Type
Content
text/html; charset=UTF-8

Server Headers

Server
Server
nginx

CORS Headers

No CORS headers found

Cookies Headers

No cookies headers found

Other Headers

Date
Other
Sat, 09 May 2026 06:19:18 GMT
Via
Other
Acquia Platform CDN 1.244
X-Acquia-View
Other
1
X-Ah-Environment
Other
prod
X-Cache
Other
HIT, HIT
X-Cache-Hits
Other
170, 0
X-Content-Security-Policy
Other
default-src 'self'; script-src 'unsafe-inline' 'unsafe-eval' 'self' *.bizzdesign.com pi.pardot.com www.google.com www.gstatic.com www.googletagmanager.com cdn.jsdelivr.net www.google-analytics.com *.googleadservices.com www.youtube.com *.wistia.com browser.sentry-cdn.com bizzdesign.chilipiper.com *.alfabetcloud.com cdn-cookieyes.com *.bing.com *.licdn.com *.oktopost.com js.zi-scripts.com tag.aticdn.net www.redditstatic.com a.quora.com bizzdesign.chilipiper.com fast.wistia.net api.ipify.org moderate.cleantalk.org fd.cleantalk.org dywrfp5ctng3l.cloudfront.net cdn.intellimize.co blob: ; object-src 'self' *.bizzdesign.com; style-src 'unsafe-inline' 'self' *.bizzdesign.com cdn.jsdelivr.net dywrfp5ctng3l.cloudfront.net; img-src data: 'self' *.bizzdesign.com *.bing.com cdn-cookieyes.com *.linkedin.com *.bing.com cdn-cookieyes.com www.googletagmanager.com *.google.com *.google.fr *.google.be *.google.de *.google.nl *.google.co.uk *.google.es q.quora.com alb.reddit.com bizzdesign.chilipiper.com stats.g.doubleclick.net *.wistia.com; media-src data: 'self' *.bizzdesign.com blob:; frame-src 'self' td.doubleclick.net www.googletagmanager.com www.youtube.com *.bizzdesign.com bizzdesign.chilipiper.com splunk-prod.alfabetcloud.com fast.wistia.net www.google.com fast.wistia.net ; frame-ancestors 'self' *.bizzdesign.com enablement.bizzdesign.com engagement.bizzdesign.com admin.mindtickle.com bizzdesign.mindtickle.com browser.sentry-cdn.com ; child-src 'self' *.bizzdesign.com ; font-src 'self' *.bizzdesign.com fonts.gstatic.com *.wistia.com; connect-src 'self' *.bizzdesign.com px.ads.linkedin.com *.clarity.ms bat.bing.net js.zi-scripts.com google.com *.google.com ws.zoominfo.com bat.bing.com www.google-analytics.com *.doubleclick.net scout.salesloft.com *.googlesyndication.com *.google-analytics.com *.googleadservices.com *.hotjar.io wss://ws.hotjar.com *.cookieyes.com cdn-cookieyes.com gjzbjmh.pa-cd.com pixel-config.reddit.com www.redditstatic.com cdn.jsdelivr.net bizzdesign.chilipiper.com pipedream.wistia.com fast.wistia.net fd.cleantalk.org bizzdesign.pinpointhq.com *.wistia.com browser.sentry-cdn.com log.intellimize.co; report-uri /policies/privacy-policy; upgrade-insecure-requests
X-Drupal-Cache
Other
HIT
X-Drupal-Dynamic-Cache
Other
MISS
X-Request-Id
Other
v-537b7440-4abc-11f1-8c6d-7f518fc58aed
X-Served-By
Other
cache-bos-kbos510020-BOS
X-Timer
Other
S1778307559.545592,VS0,VE2
X-Webkit-Csp
Other
default-src 'self'; script-src 'unsafe-inline' 'unsafe-eval' 'self' *.bizzdesign.com pi.pardot.com www.google.com www.gstatic.com www.googletagmanager.com cdn.jsdelivr.net www.google-analytics.com *.googleadservices.com www.youtube.com *.wistia.com browser.sentry-cdn.com bizzdesign.chilipiper.com *.alfabetcloud.com cdn-cookieyes.com *.bing.com *.licdn.com *.oktopost.com js.zi-scripts.com tag.aticdn.net www.redditstatic.com a.quora.com bizzdesign.chilipiper.com fast.wistia.net api.ipify.org moderate.cleantalk.org fd.cleantalk.org dywrfp5ctng3l.cloudfront.net cdn.intellimize.co blob: ; object-src 'self' *.bizzdesign.com; style-src 'unsafe-inline' 'self' *.bizzdesign.com cdn.jsdelivr.net dywrfp5ctng3l.cloudfront.net; img-src data: 'self' *.bizzdesign.com *.bing.com cdn-cookieyes.com *.linkedin.com *.bing.com cdn-cookieyes.com www.googletagmanager.com *.google.com *.google.fr *.google.be *.google.de *.google.nl *.google.co.uk *.google.es q.quora.com alb.reddit.com bizzdesign.chilipiper.com stats.g.doubleclick.net *.wistia.com; media-src data: 'self' *.bizzdesign.com blob:; frame-src 'self' td.doubleclick.net www.googletagmanager.com www.youtube.com *.bizzdesign.com bizzdesign.chilipiper.com splunk-prod.alfabetcloud.com fast.wistia.net www.google.com fast.wistia.net ; frame-ancestors 'self' *.bizzdesign.com enablement.bizzdesign.com engagement.bizzdesign.com admin.mindtickle.com bizzdesign.mindtickle.com browser.sentry-cdn.com ; child-src 'self' *.bizzdesign.com ; font-src 'self' *.bizzdesign.com fonts.gstatic.com *.wistia.com; connect-src 'self' *.bizzdesign.com px.ads.linkedin.com *.clarity.ms bat.bing.net js.zi-scripts.com google.com *.google.com ws.zoominfo.com bat.bing.com www.google-analytics.com *.doubleclick.net scout.salesloft.com *.googlesyndication.com *.google-analytics.com *.googleadservices.com *.hotjar.io wss://ws.hotjar.com *.cookieyes.com cdn-cookieyes.com gjzbjmh.pa-cd.com pixel-config.reddit.com www.redditstatic.com cdn.jsdelivr.net bizzdesign.chilipiper.com pipedream.wistia.com fast.wistia.net fd.cleantalk.org bizzdesign.pinpointhq.com *.wistia.com browser.sentry-cdn.com log.intellimize.co; report-uri /policies/privacy-policy; upgrade-insecure-requests

Recommendations

Enable compression (gzip/brotli) to improve performance