Open
Cached
·
just now
22
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains
Content-Security-Policy
Basic
frame-ancestors; script-src; worker-src; +2 more
frame-ancestors https://*.monday-it.com https://monday.com https://*.monday.com https://bigbrain.me https://*.bigbrain.me https://*.teams.microsoft.com https://microsoft365.com https://*.microsoft365.com https://*.office.com https://*.cloud.microsoft https://*.microsoftonline.com https://*.office365.com https://*.microsoft.com https://webbyawards.com https://www.webbyawards.com https://msteams.backend.monday.app https://monday.lightning.force.com https://monday.force.com https://*.www.office.com https://outlook.live.com https://outlook-sdf.live.com https://msteams-eu.backend.monday.app https://msteams-au.backend.monday.app https://msteams-il.backend.monday.app https://monday.vitally.io https://monday.zendesk.com https://*.mondaymansion.com https://mondaymagic.ai https://monday-craft.pages.dev https://mondayvibe.com https://*.id.opendns.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.monday.com https://webpack.llama.fan:* https://*.microsoft.com https://*.hsforms.com https://*.pusher.com https://accounts.google.com https://ajax.googleapis.com https://api.embed.ly https://apis.google.com https://app.box.com https://appvizer.one/ariadne/v1/ariadne.js https://bat.bing.com https://cdn.broadcast.am https://cdn.simpo.io/actionbar.js https://cdn.simpo.io/simpo-client.js https://cdn.walkme.com https://cdnjs.cloudflare.com https://code.highcharts.com https://connect.facebook.net https://ct.capterra.com https://d18vk66ftlazd2.cloudfront.net https://d2c7xlmseob604.cloudfront.net https://edge.fullstory.com https://rs.fullstory.com https://googleads.g.doubleclick.net https://js.hsforms.net https://js.live.net https://maps.googleapis.com https://monday.com https://s.pinimg.com https://s.ytimg.com https://snap.licdn.com https://snippet.growsumo.com https://songbird.cardinalcommerce.com https://static.cloudflareinsights.com https://static.zdassets.com https://tpc.googlesyndication.com https://translate.googleapis.com https://*.zopim.com https://*.smooch.io https://pod-18.zendesk.com https://ws.bluesnap.com https://www.dropbox.com https://*.google-analytics.com https://www.google.com https://www.googleadservices.com https://www.googletagmanager.com https://www.gstatic.com https://www.youtube.com https://bigbrain.me https://*.bigbrain.me https://js.appboycdn.com/web-sdk/3.2/appboy.no-amd.min.js https://js.appboycdn.com/web-sdk/3.2/appboy.min.js https://sdk.iad-06.braze.com https://*.cdn2.monday.app https://js.braintreegateway.com https://assets.braintreegateway.com https://*.paypal.com https://browser.sentry-cdn.com https://*.hotjar.com https://static.ads-twitter.com https://analytics.twitter.com https://analytics.tiktok.com https://s.yimg.jp/images/listing/tool/cv/ytag.js https://cdn.linkedin.oribi.io https://cdn.servicebell.com https://api.servicebell.com wss://api.servicebell.com wss://ws.servicebell.com https://monday.ada.support https://static.ada.support https://previews.ada.support https://rollout.ada.support https://*.everestjs.net https://*.analytics.google.com https://px.ads.linkedin.com https://a.quora.com/qevents.js https://app.birdie.so https://monday.birdie.so https://mondaycom.birdie.so https://share.birdie.so https://api.birdie.so https://cdn.birdie.so https://proxy.birdie.so https://storm.birdie.so wss://sock.birdie.so wss://sockp.birdie.so https://assets.calendly.com https://calendly.com https://cdn.cookiehub.eu https://monday.ixopay.com https://secure.ixopay.com https://*.id.opendns.com https://unpkg.com/@elevenlabs/[email protected]/dist/index.js https://c.daily.co https://cdn.merge.dev https://ah-cdn.merge.dev https://launcher.1mind.com; worker-src 'self' 'unsafe-inline' blob:; connect-src 'self' https://*.monday.com https://monday.com wss://webpack.llama.fan:* https://webpack.llama.fan:* https://grsm.io https://forms.hsforms.com https://*.algolia.net https://*.algolianet.com https://bat.bing.com https://*.braze.com https://api.smartling.com https://us-central1-adaptive-growth.cloudfunctions.net https://appvizer.one https://www.facebook.com https://graph.microsoft.com https://graph.facebook.com https://api.giphy.com https://storage.monday.app https://broadcast.am https://stats.g.doubleclick.net https://edge.fullstory.com https://rs.fullstory.com https://*.cloudfront.net https://dapulse-res.cloudinary.com https://static.cloudflareinsights.com https://*.bigbrain.me https://www.dropbox.com https://www.googletagmanager.com https://ipinfo.io https://*.cardinalcommerce.com https://www.bluesnap.com https://connect.facebook.net https://app.box.com https://code.highcharts.com https://js.live.net https://monday.zendesk.com https://monday-enterprise.zendesk.com https://static.zdassets.com https://ekr.zdassets.com https://ekr.zendesk.com https://maps.googleapis.com wss://*.pusher.com https://*.pusher.com wss://*.zopim.com https://*.zopim.com wss://*.smooch.io wss://api.smooch.io/faye https://*.smooch.io wss://*.zendesk.com/sc/faye https://*.google-analytics.com https://api.simpo.io https://cdn.simpo.io https://zh081jts88wj.statuspage.io https://www.googleapis.com https://api.braintreegateway.com https://client-analytics.braintreegateway.com https://*.braintree-api.com https://*.paypal.com https://*.sentry.io https://cdn.jsdelivr.net https://prod-use1-crm-billing.s3.amazonaws.com https://prod-use1-crm-communication.s3.amazonaws.com https://prod-use1-importer-uploads.s3.amazonaws.com https://prod-use1-uploads-raw.s3.amazonaws.com https://files-monday-com.s3.amazonaws.com https://prod-apse2-crm-billing.s3.ap-southeast-2.amazonaws.com https://prod-apse2-crm-communication.s3.ap-southeast-2.amazonaws.com https://prod-apse2-importer-uploads.s3.ap-southeast-2.amazonaws.com https://prod-apse2-uploads-raw.s3.ap-southeast-2.amazonaws.com https://prod-apse2-marketing-template-editor-templates.s3.ap-southeast-2.amazonaws.com https://prod-use1-marketing-template-editor-templates.s3.us-east-1.amazonaws.com https://prod-euc1-marketing-template-editor-templates.s3.eu-central-1.amazonaws.com https://prod-apse2-files-monday-com.s3.amazonaws.com https://prod-euc1-crm-billing.s3.eu-central-1.amazonaws.com https://prod-euc1-crm-communication.s3.eu-central-1.amazonaws.com https://prod-euc1-importer-uploads.s3.eu-central-1.amazonaws.com https://prod-ilc1-importer-uploads.s3.il-central-1.amazonaws.com https://prod-euc1-uploads-raw.s3.eu-central-1.amazonaws.com https://prod-ilc1-uploads-raw.s3.il-central-1.amazonaws.com https://prod-euc1-files-monday-com.s3.amazonaws.com https://prod-ilc1-files-monday-com.s3.il-central-1.amazonaws.com https://prod-use1-quotes-and-invoices.s3.us-east-1.amazonaws.com https://prod-euc1-quotes-and-invoices.s3.eu-central-1.amazonaws.com https://prod-apse2-quotes-and-invoices.s3.ap-southeast-2.amazonaws.com https://*.hotjar.com https://*.hotjar.io https://static.ads-twitter.com https://analytics.twitter.com https://analytics.tiktok.com https://s.yimg.jp/images/listing/tool/cv/ytag.js https://cdn.linkedin.oribi.io https://cdn.servicebell.com https://api.servicebell.com wss://api.servicebell.com wss://*.hotjar.com wss://ws.servicebell.com https://browser-intake-datadoghq.eu https://cdnjs.cloudflare.com https://fonts.gstatic.com https://fonts.googleapis.com https://googleads.g.doubleclick.net https://snap.licdn.com https://www.google.com https://monday.ada.support https://monday-gen.ada.support https://monday-gen-sandbox3.ada.support https://browser-http-intake.logs.datadoghq.com https://static.ada.support https://previews.ada.support https://rollout.ada.support https://*.everestjs.net https://*.demdex.net https://*.analytics.google.com https://px.ads.linkedin.com https://*.quora.com https://www.ojrq.net https://logs-01.loggly.com https://mondaycom.sjv.io https://insight.adsrvr.org https://analytics.google.com https://api.hsforms.com https://*.hightouch-events.com https://google.com/pagead/form-data/933380251 https://google.com/ccm/form-data/933380251 https://app.birdie.so https://monday.birdie.so https://mondaycom.birdie.so https://share.birdie.so https://api.birdie.so https://cdn.birdie.so https://proxy.birdie.so https://storm.birdie.so wss://sock.birdie.so wss://sockp.birdie.so https://cookiehub.net https://prod-apse2-widget-images-storage.s3.ap-southeast-2.amazonaws.com https://prod-euc1-widget-images-storage.s3.eu-central-1.amazonaws.com https://prod-use1-widget-images-storage.s3.us-east-1.amazonaws.com https://prod-ilc1-widget-images-storage.s3.il-central-1.amazonaws.com https://cdn.cookiehub.eu https://*.mondayprograms.com https://monday.ixopay.com https://secure.ixopay.com https://*.id.opendns.com https://www.googleadservices.com https://ad.doubleclick.net https://proxy.kapa.ai https://kapa-widget-proxy-la7dkmplpq-uc.a.run.app https://metrics.kapa.ai https://hcaptcha.com https://*.hcaptcha.com https://accounts.google.com/gsi/ https://api.eu.residency.elevenlabs.io wss://api.eu.residency.elevenlabs.io https://api.merge.dev https://ah-api.merge.dev https://ah-cdn.merge.dev https://prod-use1-ai-app-builder-vibe-user-file-uploads.s3.us-east-1.amazonaws.com https://prod-apse2-ai-app-builder-vibe-user-file-uploads.s3.ap-southeast-2.amazonaws.com https://prod-euc1-ai-app-builder-vibe-user-file-uploads.s3.eu-central-1.amazonaws.com https://prod-ilc1-ai-app-builder-vibe-user-file-uploads.s3.il-central-1.amazonaws.com https://prod-ilc1-marketing-template-editor-templates.s3.il-central-1.amazonaws.com https://prod-apse2-marketing-channels-brand-assets.s3.ap-southeast-2.amazonaws.com https://prod-euc1-marketing-channels-brand-assets.s3.eu-central-1.amazonaws.com https://prod-ilc1-marketing-channels-brand-assets.s3.il-central-1.amazonaws.com https://prod-use1-marketing-channels-brand-assets.s3.us-east-1.amazonaws.com https://launcher.prd-b.1mind.com https://launcher.prd-g.1mind.com https://launcher.1mind.com https://monday-websitebdr-prod.1mind.com https://*.vapi.ai wss://*.vapi.ai https://*.daily.co wss://*.daily.co; report-uri https://o916138.ingest.us.sentry.io/api/4507803872198656/security/?sentry_key=8e1fb7e952d4abfd146752c94791f51a&sentry_environment=production;
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Present
same-origin
Permissions-Policy
Missing
Not configured
Recommendations
- • Consider adding 'preload' to HSTS for maximum security
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Consider adding Permissions-Policy to control browser features
Performance Headers
3 headers
Connection
Performance
close
Transfer-Encoding
Performance
chunked
Vary
Performance
Accept-Encoding
Caching Headers
1 headers
Cache-Control
Caching
max-age=0, private, must-revalidate
Content Headers
1 headers
Content-Type
Content
text/html; charset=utf-8
Server Headers
2 headers
Server
Server
cloudflare
X-Runtime
Server
1.148553
CORS Headers
0 headers
No CORS headers found
Cookies Headers
1 headers
Set-Cookie
Cookies
_cfuvid=NIvWC_ZUmoUubDLPi3iOxyt9B8IjlfPJx1nTy8wcxXk-1769500739269-0.0.1.1-604800000; path=/; domain=.monday.com; HttpOnly; Secure; SameSite=None
Other Headers
10 headers
Cf-Cache-Status
Other
DYNAMIC
Cf-Ray
Other
9c46b53cfde6a3be-IAD
Date
Other
Tue, 27 Jan 2026 07:58:59 GMT
P3p
Other
CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT"
Server-Timing
Other
amb_upstream_time;dur=1152
X-Envoy-Upstream-Service-Time
Other
1152
X-Monday-Rgn
Other
use1
X-Request-Id
Other
835054d5-b9aa-9f07-b815-2c4d88ae2493
X-Robots-Tag
Other
none
X-Sbt
Other
1769435593
Recommendations
Enable compression (gzip/brotli) to improve performance