Open
Cached
·
just now
20
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000
Content-Security-Policy
Weak
frame-ancestors
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
no-referrer-when-downgrade
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Significantly strengthen CSP directives
- • Consider adding Permissions-Policy to control browser features
Performance Headers
3 headers
Accept-Ranges
Performance
none
Connection
Performance
close
Vary
Performance
Accept-Encoding
Caching Headers
4 headers
Cache-Control
Caching
public, max-age=3600, s-maxage=0
Etag
Caching
"535a7-Zlq10ghVMju4RURLnddMS5nk3xM"
Expires
Caching
Sun, 28 Dec 2025 23:46:08 GMT
Last-Modified
Caching
Sun, 28 Dec 2025 22:46:08 GMT
Content Headers
2 headers
Content-Length
Content
341415
Content-Type
Content
text/html; charset=utf-8
Server Headers
0 headers
No server headers found
CORS Headers
1 headers
Access-Control-Allow-Origin
Cors
*
Cookies Headers
0 headers
No cookies headers found
Other Headers
4 headers
Accept-Ch
Other
DPR, Width, Viewport-Width
Content-Security-Policy-Report-Only
Other
default-src 'self' *.creative.com d1ltlumq33lgbo.cloudfront.net d287ku8w5owj51.cloudfront.net *.crazyegg.com im-yacms.s3.ap-southeast-1.amazonaws.com *.zdassets.com *.zendesk.com *.zopim.com zendesk-eu.my.sentry.io wss://creativesupporthelp.zendesk.com;script-src 'self' 'unsafe-eval' 'unsafe-inline' *.awin1.com *.bootstrapcdn.com *.crazyegg.com *.creative.com *.dwin1.com *.facebook.com *.google-analytics.com *.google.com *.gstatic.com *.mlytics.com *.ads-twitter.com ads-api.twitter.com analytics.twitter.com ajax.googleapis.com b91.yahoo.co.jp beacon.cdn.mile.cloud blueimp.github.io browser-update.org cdn.jsdelivr.net cdn.moengage.com cdnjs.cloudflare.com code.jquery.com connect.facebook.net cv.valuecommerce.com d.line-scdn.net d287ku8w5owj51.cloudfront.net dnn506yrbagrg.cloudfront.net googleads.g.doubleclick.net graph.facebook.com images.soundblaster.com lantern.roeyecdn.com platform.twitter.com remote.captcha.com s.yimg.jp sdk.amazonaws.com sslwidget.criteo.com static.criteo.net csm.da.us.criteo.net static.zdassets.com tagmanager.google.com tpay.com *.googlesyndication.com trj.valuecommerce.com use.typekit.net widget-mediator.zopim.com widget.us.criteo.com www.googleadservices.com www.googletagmanager.com www.youtube.com analytics.tiktok.com creativelabs.postaffiliatepro.com;style-src 'self' 'unsafe-inline' *.creative.com d1ltlumq33lgbo.cloudfront.net d287ku8w5owj51.cloudfront.net *.typekit.net *.adobe.com *.google.com tagmanager.google.com fonts.googleapis.com fonts.gstatic.com/ *.crazyegg.com *.bootstrapcdn.com cdnjs.cloudflare.com www.jqueryscript.net www.soundblaster.com www.gstatic.com;img-src 'self' blob: *.awin1.com *.crazyegg.com *.creative.com *.dwin1.com *.google-analytics.com *.imgvc.com *.mlytics.com adservice.google.com *.ads-twitter.com ads-api.twitter.com analytics.twitter.com b91.yahoo.co.jp beacon.cdn.mile.cloud browser-update.org contextual.media.net criteo-partners.tremorhub.com csm.va.us.criteo.net d1ltlumq33lgbo.cloudfront.net d287ku8w5owj51.cloudfront.net data: dis.criteo.com encrypted-tbn0.gstatic.com encrypted-tbn1.gstatic.com encrypted-tbn2.gstatic.com encrypted-tbn3.gstatic.com exchange.mediavine.com google.com.sg googleads.g.doubleclick.net graph.facebook.com gum.criteo.com h.online-metrix.net i.vimeocdn.com i.ytimg.com im-yacms.s3.ap-southeast-1.amazonaws.com image-eu.moengage.com img.youtube.com itag.valuecommerce.com itag.valuecommerce.ne.jp lantern.roeye.com p.typekit.net ssl.gstatic.com static.criteo.net static.zdassets.com stats.g.doubleclick.net sync-criteo.ads.yieldmo.com sync-t1.taboola.com t.co tpay.com tr.line.me translate.google.com translate.googleapis.com use.typekit.net v2assets.zopim.io www.adobe.com www.facebook.com www.google-analytics.com www.google.ae www.google.at www.google.az www.google.ba www.google.be www.google.bg www.google.by www.google.ca www.google.ch www.google.cl www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.co.nz www.google.co.th www.google.co.uk www.google.co.ve www.google.co.za www.google.com www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bo www.google.com.br www.google.com.co www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.gt www.google.com.hk www.google.com.kw www.google.com.mt www.google.com.mx www.google.com.my www.google.com.np www.google.com.pa www.google.com.pe www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.sa www.google.com.sg www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.vn www.google.cz www.google.de www.google.dk www.google.ee www.google.es www.google.fi www.google.fr www.google.gr www.google.hr www.google.hu www.google.ie www.google.iq www.google.it www.google.lk www.google.lt www.google.lu www.google.lv www.google.kz www.google.mk www.google.nl www.google.no www.google.pl www.google.pt www.google.ro www.google.rs www.google.ru www.google.se www.google.si www.google.sk www.google.tt *.googlesyndication.com www.googletagmanager.com www.gstatic.com www.paypalobjects.com www.soundblaster.com www.youtube.com tbs.tradedoubler.com;font-src 'self' *.creative.com d1ltlumq33lgbo.cloudfront.net d287ku8w5owj51.cloudfront.net fonts.gstatic.com use.typekit.net data: *.bootstrapcdn.com cdnjs.cloudflare.com www.jqueryscript.net file.myfontastic.com www.slant.co cdn.honey.io;child-src blob: www.google.com cdn.moengage.com;connect-src 'self' *.cdnsuehprom.com *.cloud-button.com *.crazyegg.com *.creative.com *.daxinlicai.com *.google-analytics.com *.googlesyndication.com *.mlytics.com *.sphgfgx.com accounts.google.com ad.doubleclick.net adservice.google.com analytics.google.com *.ads-twitter.com ads-api.twitter.com analytics.twitter.com autocomplete-api.smartystreets.com cdn.contentful.com code.jquery.com cognito-identity.ap-southeast-1.amazonaws.com cognito-identity.ap-northeast-1.amazonaws.com contextual.media.net creativesupporthelp.zendesk.com criteo-partners.tremorhub.com criteo-sync.teads.tv d287ku8w5owj51.cloudfront.net ekr.zdassets.com exchange.mediavine.com google.com graph.facebook.com if1k4cyjr4.execute-api.ap-southeast-1.amazonaws.com measurement-api.criteo.com oxrz6c4lbi.execute-api.ap-southeast-1.amazonaws.com pay.google.com performance.typekit.net region1.analytics.google.com sdk-02.moengage.com securepubads.g.doubleclick.net spay.samsung.com sslwidget.criteo.com static.criteo.net stats.g.doubleclick.net sync-criteo.ads.yieldmo.com sync-t1.taboola.com sync.outbrain.com t.co tez.google.com *.googleapis.com wss://widget-mediator.zopim.com www.facebook.com www.google-analytics.com www.google.com z-m-graph.facebook.com z-p3-graph.facebook.com analytics.tiktok.com;frame-src 'self' data: *.crazyegg.com accounts.google.com ad.gunosy.com cdn.moengage.com creativesupporthelp.zendesk.com d1ltlumq33lgbo.cloudfront.net d287ku8w5owj51.cloudfront.net fledge.us.criteo.com googleads.g.doubleclick.net gum.criteo.com pay.google.com player.vimeo.com static.criteo.net td.doubleclick.net tpc.googlesyndication.com www.facebook.com www.google.co.jp www.google.com www.youtube.com www.youtube-nocookie.com;media-src data: *.creative.com d1ltlumq33lgbo.cloudfront.net d287ku8w5owj51.cloudfront.net cn-img.creative.com;worker-src 'self' blob: *.creative.com;frame-ancestors 'self' *.creative.com img.stage.creative.com appsmith.dev.creative.com;object-src 'none';upgrade-insecure-requests;report-uri https://api.creative.com/csp/report/;
Date
Other
Sun, 28 Dec 2025 22:46:08 GMT
X-Ua-Compatible
Other
IE=edge
Recommendations
Enable compression (gzip/brotli) to improve performance
Analysis completed in 4388ms