Open
Cached
·
just now
17
Headers
Detected Technologies from Headers
Akamai
Amplitude
Microsoft Advertising
DigiCert
Facebook
Google AdSense
Google Analytics
Google API JS Client
Google Cloud Storage
Google DoubleClick
Google Fonts
Google Hosted Libraries
Google IMA SDK
Google Search
Google Tag Manager
Imgix
New Relic
Plaid
Qualtrics
Tealium
Vimeo
WordPress
WordPress.com
WordPress VIP
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000; includeSubdomains; preload
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close, Transfer-Encoding
Transfer-Encoding
chunked
connection: close, Transfer-Encoding transfer-encoding: chunked
Caching Headers
Cache-Control
max-age=0, no-cache, no-store
Expires
Thu, 04 Jun 2026 10:10:25 GMT
Pragma
no-cache
cache-control: max-age=0, no-cache, no-store expires: Thu, 04 Jun 2026 10:10:25 GMT pragma: no-cache
Content Headers
Content-Type
text/html; charset=utf-8
content-type: text/html; charset=utf-8
Server Headers
Server
CK-FG-server
server: CK-FG-server
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Date
Thu, 04 Jun 2026 10:10:25 GMT
Origin-Dc
us-east4
Origin-Env
production
X-Goog-Meta-X-Powered-By
GCS-UTS-FALLBACK
date: Thu, 04 Jun 2026 10:10:25 GMT origin-dc: us-east4 origin-env: production x-akamai-transformed: 0 - 0 - x-goog-meta-x-powered-by: GCS-UTS-FALLBACK
Recommendations
Enable compression (gzip/brotli) to improve performance