Open
Cached
·
just now
21
Headers
Detected Technologies from Headers
AWS CloudFront
Tailwind CSS
YouTube
AWS
Active incidents
Amazon S3
Microsoft Advertising
ClickCease
Cloudflare CDN
Cloudflare Web Analytics
Cookiebot
Craft CMS
Crazy Egg
Dreamdata
Google AdSense
Google Analytics
Google DoubleClick
Google Hosted Libraries
Google Search
Google Tag Manager
HubSpot
HubSpot Analytics
HubSpot CMS
HubSpot Forms
HubSpot Live Chat
jsDelivr
LinkedIn
Microsoft Clarity
Navattic
Spotify
Typeform
Vector
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=15552000
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
Transfer-Encoding
chunked
Vary
accept-encoding
connection: close transfer-encoding: chunked vary: accept-encoding
Caching Headers
Cache-Control
public, s-maxage=31536000, max-age=0
cache-control: public, s-maxage=31536000, max-age=0
Content Headers
Content-Type
text/html; charset=UTF-8
content-type: text/html; charset=UTF-8
Server Headers
server: cloudflare x-powered-by: Craft CMS,Blitz
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Alt-Svc
h3=":443"; ma=86400
Clear-Site-Data
"cache"
Date
Thu, 21 May 2026 09:47:36 GMT
Reporting-Endpoints
csp-endpoint="https://www.cheqroom.com/csp-report"
Server-Timing
cfCacheStatus;desc="BYPASS", cfEdge;dur=10,cfOrigin;dur=126
Speculation-Rules
"/cdn-cgi/speculation"
alt-svc: h3=":443"; ma=86400 cf-cache-status: BYPASS cf-ray: 9ff2a921cf3f058b-IAD clear-site-data: "cache" date: Thu, 21 May 2026 09:47:36 GMT reporting-endpoints: csp-endpoint="https://www.cheqroom.com/csp-report" server-timing: cfCacheStatus;desc="BYPASS", cfEdge;dur=10,cfOrigin;dur=126 speculation-rules: "/cdn-cgi/speculation"
Recommendations
Enable compression (gzip/brotli) to improve performance
Consider removing X-Powered-By header to hide server technology