Open
Cached
·
just now
19
Headers
Detected Technologies from Headers
AWS CloudFront
PayPal
Amplitude
Amazon S3
Microsoft Advertising
Braintree
Cloudflare CDN
Contentful
Datadog
Envoy
Facebook
Google Analytics
Google API JS Client
Google DoubleClick
Google Fonts
Google reCAPTCHA
Google Search
Google Static File Front End
Google Tag Manager
Mixpanel
New Relic
Segment
Trustpilot
Google Cloud
HTTP Security Headers
Status
Strict-Transport-Security
Excellent
max-age=31536000; includeSubDomains; preload
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
Transfer-Encoding
chunked
Vary
RSC, Next-Router-State-Tree, Next-Router-Prefetch, Accept-Encoding
connection: close transfer-encoding: chunked vary: RSC, Next-Router-State-Tree, Next-Router-Prefetch, Accept-Encoding
Caching Headers
Cache-Control
no-cache, no-store
cache-control: no-cache, no-store
Content Headers
Content-Type
text/html; charset=utf-8
content-type: text/html; charset=utf-8
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Date
Sat, 09 May 2026 09:59:25 GMT
X-Xoom-Requestid
7310e4a6-b358-46ba-9417-56942d4bb8a8
X-Xoom-Traceid
6833283040628566618
cf-cache-status: DYNAMIC cf-ray: 9f8fd9ed8c76c095-IAD date: Sat, 09 May 2026 09:59:25 GMT x-envoy-upstream-service-time: 55 x-xoom-requestid: 7310e4a6-b358-46ba-9417-56942d4bb8a8 x-xoom-traceid: 6833283040628566618
Recommendations
Enable compression (gzip/brotli) to improve performance