Open
Cached
·
just now
26
Headers
Detected Technologies from Headers
PayPal
AWS CloudFront
Google AdSense
Google Tag Manager
Google Translate
Webflow
CDN77
Envoy
Google DoubleClick
Google Analytics
Dropbox
Baidu Analytics
Segment
Google Static File Front End
LaunchDarkly
Google API JS Client
Google Fonts
Perplexity AI
Algolia
Qualtrics
unpkg
Google Search
Yandex
Microsoft SharePoint
Facebook
Amazon S3
OneTrust
GitHub
Adobe Fonts (Typekit)
Cloudflare CDNJS
AWS
Active incidents
Vimeo
TrustArc
ipify
Zoho Mail
HubSpot
YouTube
Font Awesome
jsDelivr
Google Cloud
Express
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000
Content-Security-Policy-Report-Only
Basic
base-uri; block-all-mixed-content; connect-src; +10 more
Analyze
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
Vary
Accept-Encoding
connection: close vary: Accept-Encoding
Caching Headers
Cache-Control
private,no-cache,no-store,pre-check=0,post-check=0,must-revalidate
Etag
W/"3f8a9-FVC428Nw+DM2oM89aTo8UoULmYQ"
Expires
-1
Pragma
no-cache
cache-control: private,no-cache,no-store,pre-check=0,post-check=0,must-revalidate etag: W/"3f8a9-FVC428Nw+DM2oM89aTo8UoULmYQ" expires: -1 pragma: no-cache
Content Headers
Content-Length
260265
Content-Type
text/html; charset=utf-8
content-length: 260265 content-type: text/html; charset=utf-8
Server Headers
server: istio-envoy x-powered-by: Express
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Date
Mon, 01 Jun 2026 10:32:18 GMT
Intuit_tid
1-6a1d5fb2-644629b10b8ecc644103b56e
Server-Timing
pluginConfigs;dur=1.03,appMw;dur=0.02,ixpAssignments;dur=0.03,appPostAuthMw;dur=0.02,shellServiceMw;dur=3.19,totalMwExecTime;dur=50.16
X-Dns-Prefetch-Control
off
X-Download-Options
noopen
X-Intuit-Upstream-Locality-Region
us-west-2
X-Request-Id
1-6a1d5fb2-644629b10b8ecc644103b56e
X-Spanid
b8989595-01d7-cbc7-bf2a-4da98559ba94
date: Mon, 01 Jun 2026 10:32:18 GMT intuit_tid: 1-6a1d5fb2-644629b10b8ecc644103b56e server-timing: pluginConfigs;dur=1.03,appMw;dur=0.02,ixpAssignments;dur=0.03,appPostAuthMw;dur=0.02,shellServiceMw;dur=3.19,totalMwExecTime;dur=50.16 x-amzn-trace-id: Root=1-6a1d5fb2-644629b10b8ecc644103b56e x-dns-prefetch-control: off x-download-options: noopen x-envoy-upstream-service-time: 70 x-intuit-upstream-locality-region: us-west-2 x-request-id: 1-6a1d5fb2-644629b10b8ecc644103b56e x-spanid: b8989595-01d7-cbc7-bf2a-4da98559ba94
Recommendations
Enable compression (gzip/brotli) to improve performance
Consider removing X-Powered-By header to hide server technology