Open
Cached
·
just now
19
Headers
Detected Technologies from Headers
AWS CloudFront
Algolia
AWS
Amazon S3
Azure Blob Storage
BugHerd
Bugsnag
Calendly
Cloudflare CDN
Facebook
Google Analytics
Google API JS Client
Google DoubleClick
Google Fonts
Google reCAPTCHA
Google Search
Google Sign-In
hCaptcha
Hotjar
HubSpot Forms
jsDelivr
Mixpanel
New Relic
PostHog
Pusher
Sentry
Stripe
Yellow.ai
YouTube
Zendesk
HTTP Security Headers
Status
Strict-Transport-Security
Excellent
max-age=31536000; includeSubDomains; preload
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
no-referrer
Permissions-Policy
Missing
Not configured
Recommendations
- • Strengthen CSP by removing 'unsafe-eval'
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
Transfer-Encoding
chunked
connection: close transfer-encoding: chunked
Caching Headers
Cache-Control
no-store
Expires
0
cache-control: no-store expires: 0
Content Headers
Content-Type
text/html; charset=utf-8
content-type: text/html; charset=utf-8
CORS Headers
Access-Control-Allow-Credentials
true
Access-Control-Allow-Headers
Accept,Authorization,Cache-Control,Content-Type,DNT,If-Modified-Since,Keep-Alive,Origin,User-Agent,X-Requested-With,bot,platform,Responsetype
Access-Control-Allow-Methods
GET, POST, OPTIONS, PUT, DELETE, HEAD, PATCH
access-control-allow-credentials: true access-control-allow-headers: Accept,Authorization,Cache-Control,Content-Type,DNT,If-Modified-Since,Keep-Alive,Origin,User-Agent,X-Requested-With,bot,platform,Responsetype access-control-allow-methods: GET, POST, OPTIONS, PUT, DELETE, HEAD, PATCH
Cookies Headers
Other Headers
Date
Wed, 01 Apr 2026 09:20:45 GMT
Feature-Policy
geolocation 'self'
cf-cache-status: DYNAMIC cf-ray: 9e568507dcee9bd3-IAD date: Wed, 01 Apr 2026 09:20:45 GMT feature-policy: geolocation 'self'
Recommendations
Enable compression (gzip/brotli) to improve performance