Open
Cached
·
just now
25
Headers
Detected Technologies from Headers
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=3600;includeSubDomains
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
Transfer-Encoding
chunked
Vary
Accept-Encoding
connection: close transfer-encoding: chunked vary: Accept-Encoding
Caching Headers
Cache-Control
public, max-age=3600
cache-control: public, max-age=3600
Content Headers
Content-Type
text/html;charset=UTF-8
content-type: text/html;charset=UTF-8
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Cdn-Cache
HIT
Cdn-Cachedat
05/24/2026 02:50:30
Cdn-Edgestorageid
1235
Cdn-Proxyver
1.53
Cdn-Pullzone
320099
Cdn-Requestcountrycode
US
Cdn-Requestid
0e45681d56356db2eda0912dcc20f0ae
Cdn-Requestpullcode
200
Cdn-Requestpullsuccess
True
Cdn-Requesttime
0
Cdn-Status
200
Date
Sun, 24 May 2026 02:54:57 GMT
X-Dot-Server
dotcms-demo-74fbdc944-jwtkf|a262169984
X-Dotratelimit-Toks-Max
10000/10000
X-Dotrequest-Cost
2.00
cdn-cache: HIT cdn-cachedat: 05/24/2026 02:50:30 cdn-edgestorageid: 1235 cdn-proxyver: 1.53 cdn-pullzone: 320099 cdn-requestcountrycode: US cdn-requestid: 0e45681d56356db2eda0912dcc20f0ae cdn-requestpullcode: 200 cdn-requestpullsuccess: True cdn-requesttime: 0 cdn-status: 200 date: Sun, 24 May 2026 02:54:57 GMT link: <https://demo.dotcms.com/>; rel="canonical" x-dot-server: dotcms-demo-74fbdc944-jwtkf|a262169984 x-dotratelimit-toks-max: 10000/10000 x-dotrequest-cost: 2.00
Recommendations
Enable compression (gzip/brotli) to improve performance