Open
Cached
·
just now
18
Headers
Detected Technologies from Headers
AppNexus (Xandr)
Authorize.net
Amazon S3
Bing
Ceros
Cloudflare CDN
Cloudflare CDNJS
Contentsquare
Demandbase
Oracle Eloqua
GitHub
Google Analytics
Google API JS Client
Google DoubleClick
Google Fonts
Google Static File Front End
Google Tag Manager
Liveramp
Microsoft Clarity
Optimizely
YouTube
Google Cloud
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000; includeSubdomains; preload
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Present
nosniff, nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
Transfer-Encoding
chunked
Vary
Accept-Encoding
connection: close transfer-encoding: chunked vary: Accept-Encoding
Caching Headers
Age
7075
Cache-Control
public, s-maxage=3600, max-age=300, stale-while-revalidate=600, stale-if-error=3600
Last-Modified
Fri, 22 May 2026 00:01:44 GMT
age: 7075 cache-control: public, s-maxage=3600, max-age=300, stale-while-revalidate=600, stale-if-error=3600 last-modified: Fri, 22 May 2026 00:01:44 GMT
Content Headers
Content-Type
text/html;charset=utf-8
content-type: text/html;charset=utf-8
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Date
Fri, 22 May 2026 01:59:39 GMT
cf-cache-status: DYNAMIC cf-ray: 9ff8390729a5b086-IAD date: Fri, 22 May 2026 01:59:39 GMT
Recommendations
Enable compression (gzip/brotli) to improve performance