Cached · just now
23 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31536000
Content-Security-Policy
Weak
upgrade-insecure-requests
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Significantly strengthen CSP directives
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

Performance Headers

3 headers
Connection
Performance
close
Transfer-Encoding
Performance
chunked
Vary
Performance
Accept-Encoding

Caching Headers

3 headers
Cache-Control
Caching
no-store, no-cache, must-revalidate, max-age=0
Expires
Caching
-1
Pragma
Caching
no-cache

Content Headers

1 headers
Content-Type
Content
text/html; charset=UTF-8

Server Headers

1 headers
Server
Server
cloudflare

CORS Headers

0 headers
No CORS headers found

Cookies Headers

0 headers
No cookies headers found

Other Headers

10 headers
Alt-Svc
Other
h3=":443"; ma=86400
Cf-Cache-Status
Other
DYNAMIC
Cf-Ray
Other
9c396b7eb8153725-IAD
Content-Security-Policy-Report-Only
Other
worker-src blob:; form-action *.cardinalcommerce.com *.paypal.com www.sandbox.paypal.com *.amazon.com *.facebook.com *.googlesyndication.com *.tiktok.com connect.facebook.net 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src *.googletagmanager.com *.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com *.paypal.com www.sandbox.paypal.com player.vimeo.com *.google.com *.braintreegateway.com google.com js.stripe.com *.amazon.com *.payments-amazon.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com connect.facebook.net www.commercepartnerhub.com assets.braintreegateway.com plumrocket.com *.authorize.net *.artifi.net www.googleadservices.com assets.pinterest.com ct.pinterest.com www.paypalobjects.com i.liadm.com 'self' 'unsafe-inline'; script-src *.googletagmanager.com *.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net *.google.com *.newrelic.com *.nr-data.net *.authorize.net *.commerce-payment-services.com *.paypal.com www.sandbox.paypal.com www.paypalobjects.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.gstatic.com assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com *.typekit.net google.com *.cdn-apple.com *.braintreegateway.com js.stripe.com *.payments-amazon.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.jsdelivr.net *.tiktok.com *.klaviyo.com fast.a.klaviyo.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.shopify.com *.sandbox.braintreegateway.com *.popt.in *.cloudflare.com celebrosnlp.com *.celebros-analytics.com *.artifi.net maps.googleapis.com www.googletagservices.com cdn.gladly.qa cdn.gladly.com *.monetate.net *.visualwebsiteoptimizer.com *.cloudfront.net s.pinimg.com bat.bing.com tag.rmp.rakuten.com ut.rd.linksynergy.com *.pinterest.com cdn.noibu.com *.hotjar.com b-code.liadm.com secure.merchantadvantage.com static.currentcatalog.com currentc-ac.celebros.com ajax.googleapis.com *.celebros.com 'self' 'unsafe-inline' 'unsafe-eval'; report-uri https://www.currentcatalog.com/pr-csp/report/add/; report-to report-endpoint;
Date
Other
Sun, 25 Jan 2026 17:16:42 GMT
Grace
Other
none
Report-To
Other
{"group":"report-endpoint","max_age":10886400,"endpoints":[{"url":"https:\/\/www.currentcatalog.com\/pr-csp\/report\/add\/"}]}
X-Edge-Cache-Status
Other
HIT
X-Edge-Server
Other
cmg-prod-edge1
X-Origin-Server
Other
cmg-prod-web-i-08990fc9

Recommendations

Enable compression (gzip/brotli) to improve performance