24 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Weak
upgrade-insecure-requests
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Significantly strengthen CSP directives
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

Performance Headers

3 headers
Connection
Performance
close
Transfer-Encoding
Performance
chunked
Vary
Performance
Accept-Encoding

Caching Headers

3 headers
Cache-Control
Caching
max-age=86400, public, s-maxage=86400
Expires
Caching
Sun, 25 Jan 2026 20:44:20 GMT
Pragma
Caching
cache

Content Headers

1 headers
Content-Type
Content
text/html; charset=UTF-8

Server Headers

1 headers
Server
Server
cloudflare

CORS Headers

0 headers
No CORS headers found

Cookies Headers

1 headers
Set-Cookie
Cookies
X-Magento-Vary=5d076b7ffda4c580dfc41ce897ecc895e34f0416d67b7dab49b36583b74c9eaf; expires=Sat, 24-Jan-2026 21:44:21 GMT; Max-Age=3600; path=/; secure; HttpOnly; SameSite=Lax

Other Headers

11 headers
Alt-Svc
Other
h3=":443"; ma=86400
Cf-Cache-Status
Other
DYNAMIC
Cf-Ray
Other
9c325e422fbfe607-IAD
Content-Security-Policy-Report-Only
Other
font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.userway.org https://fonts.googleapis.com/ https://wsv3cdn.audioeye.com/ *.zohocdn.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com *.versapay.com *.paynup.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://www.facebook.com/ *.twitter.com *.versapay.com *.paynup.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.xtento.com https://www.facebook.com/ https://c.sproutvideo.com/ http://videos.sproutvideo.com/ https://checkout.creditkey.com/ https://td.doubleclick.net/ https://gum.criteo.com/ https://cdn.justuno.com/ https://fledge.us.criteo.com/ https://nytrng.com/ https://wsv3cdn.audioeye.com/ https://static.criteo.net/ https://www.monthlywarranty.com/ https://salesiq.zohopublic.com/ *.twitter.com *.paynup.com *.versapay.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.shopperapproved.com *.userway.org www.xtento.com cdn.xtento.com https://img.youtube.com https://www.facebook.com/ https://maps.gstatic.com/ https://c.sproutvideo.com/ https://cdn-thumbnails.sproutvideo.com/ https://creditkey-assets.s3-us-west-2.amazonaws.com/ https://www.creditkey.com/ https://maps.googleapis.com/ https://www.google.co.in/ https://www.adelixir.com/ https://bat.bing.com/ https://cdn.ywxi.net/ https://www.monthlywarranty.com/ https://shopper.shop.pe/ https://public-prod-dspcookiematching.dmxleo.com/ https://tg.socdm.com/ https://cm.g.doubleclick.net/ https://x.bidswitch.net/ https://ib.adnxs.com/ https://rtb-csync.smartadserver.com/ https://sync-t1.taboola.com/ https://r.casalemedia.com/ https://adx.dable.io/ https://cs.adingo.jp/ https://ads.stickyadstv.com/ https://ad.360yield.com/ https://idsync.rlcdn.com/ https://contextual.media.net/ https://c.bing.com/ https://sync.outbrain.com/ https://simage2.pubmatic.com/ https://pixel.rubiconproject.com/ https://s.ad.smaato.net/ https://criteo-sync.teads.tv/ https://ade.clmbtech.com/ https://eb2.3lift.com/ https://sync-criteo.ads.yieldmo.com/ https://sync.1rx.io/ https://dis.criteo.com/ https://sync.aralego.com/ https://cdn.aralego.net/ https://d3cgm8py10hi0z.cloudfront.net/ *.criteo.net/ *.criteo.com/ *.zohopublic.com/ *.zohocdn.com *.zoho.com https://redchamps.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.versapay.com *.paynup.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.userway.org www.xtento.com cdn.xtento.com s7.addthis.com https://cdn.pagesense.io/ https://connect.facebook.net/ https://cdn.searchspring.net/ http://cdn.searchspring.net/ https://static.srcspot.com/ https://maps.googleapis.com/ https://unpkg.com/ https://cdn.noibu.com/ https://bat.bing.com/ https://static.criteo.net/ https://cdn.justuno.com/ https://www.adelixir.com/ https://www.clickcease.com/ https://ca-eu.cookie-script.com/ https://shop.pe/ https://my.justuno.com/ https://d2mjzob2nc713b.cloudfront.net/ https://aly.justuno.com/ https://sslwidget.criteo.com/ https://widget.us.criteo.com/ https://wsmcdn.audioeye.com/ https://cdn.ywxi.net/ https://wsv3cdn.audioeye.com/ https://addshoppers.s3.amazonaws.com/ https://shopper.shop.pe/ https://www.trustedsite.com/ https://www.monthlywarranty.com/ *.zohopublic.com *.zohocdn.com *.zohostatic.com *.zoho.com *.avada.io *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.versapay.com *.paynup.com *.datadoghq.com https://www.googletagmanager.com tagmanager.google.com *.maxmind.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.klaviyo.com *.fontawesome.com *.shopperapproved.com *.userway.org https://fonts.googleapis.com/ http://cdn.searchspring.net/ https://c.sproutvideo.com/ https://www.monthlywarranty.com/ https://css.zohostatic.com/ *.zohopublic.com/ *.zohocdn.com/ *.zoho.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.versapay.com *.paynup.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://static.zohocdn.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.userway.org ekr.zdassets.com/ https://cdn.pagesense.io/ https://connect.facebook.net/ https://cdn.searchspring.net/ http://cdn.searchspring.net/ http://a.klaviyo.com/ *.searchspring.io/ https://maps.googleapis.com/ https://www.facebook.com/ wss://input.noibu.com/ https://cdn.noibu.com/ https://www.google.com/ https://stats.g.doubleclick.net/ https://s3-us-west-2.amazonaws.com/ https://app.shop.pe/ https://manage.safeopt.com/ https://analytics.audioeye.com/ https://input.noibu.com/ https://measurement-api.criteo.com/ https://google.com/ https://aly.justuno.com/ https://shopper.shop.pe/ https://bat.bing.com/ *.zohopublic.com wss://vts.zohopublic.com/ https://static.zohocdn.com/ *.zoho.com https://get.geojs.io *.avada.io *.cloudflare.com *.twitter.com *.twimg.com *.versapay.com *.paynup.com *.datadoghq.com https://www.google-analytics.com *.mmapiws.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri https://static.zohocdn.com 'self' 'unsafe-inline'; report-uri http://127.0.0.1/magento_os/; report-to report-endpoint;
Date
Other
Sat, 24 Jan 2026 20:44:21 GMT
Report-To
Other
{"group":"report-endpoint","max_age":10886400,"endpoints":[{"url":"http:\/\/127.0.0.1\/magento_os\/"}]}
Server-Timing
Other
cfEdge;dur=7,cfOrigin;dur=844
X-Magento-Debug
Other
1
X-Magento-Tags
Other
store,cms_b,mp_smtp_script,cms_b_call_to_order,cms_b_free_shipping,cms_b_footer_spiral_customer_support,cms_b_footer_spiral_links,cms_b_footer_spiral_bottom_links,cms_p_156,cms_b_mobile_acc_menu_contact,cms_b_spiral_top_static_menu,cms_b_848,cms_b_home-banner-spiral,cms_b_800,cms_b_home_customer_support,cms_b_802,cms_b_home_spiral_features,cms_b_801,cms_b_home_spiral_binding_style,cms_b_,cms_b_805,cms_b_home_spiral_features_product,cms_b_806,cms_b_home_spiral_nationwide,cms_b_807,cms_b_home_spiral_service_program
X-Served-By
Other
gpc127-dev2
X-Ua-Compatible
Other
IE=edge

Recommendations

Enable compression (gzip/brotli) to improve performance