Open
Cached
·
just now
22
Headers
Detected Technologies from Headers
HTTP Security Headers
Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Present
origin-when-cross-origin
Permissions-Policy
Missing
Not configured
Recommendations
- • Consider adding 'preload' to HSTS for maximum security
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
connection: close
Caching Headers
Cache-Control
private
cache-control: private
Content Headers
Content-Length
46
Content-Type
text/html; charset=utf-8
content-length: 46 content-type: text/html; charset=utf-8
CORS Headers
Access-Control-Allow-Headers
Authorization, Origin, X-Requested-With, Content-Type, Accept
Access-Control-Allow-Methods
GET, POST, OPTIONS
Access-Control-Allow-Origin
*
access-control-allow-headers: Authorization, Origin, X-Requested-With, Content-Type, Accept access-control-allow-methods: GET, POST, OPTIONS access-control-allow-origin: *
Cookies Headers
Other Headers
Date
Sun, 10 May 2026 01:20:17 GMT
P3p
CP="NOP3PPOLICY"
Status
404 Not Found
X-Content-Security-Policy
base-uri 'none'; connect-src 'self' https://www.google-analytics.com https://heapanalytics.com https://api.sprig.com/sdk/ https://sentry.io https://d.dropbox.com https://ekr.zdassets.com https://hellosign.zendesk.com wss://hellosign.zendesk.com https://www.dropbox.com/amplitude_proxy/ingest_lenient; frame-ancestors 'self'; object-src 'none'; script-src https: 'report-sample' 'nonce-tMnvbLFF9/wsbDadw9ffWwO5' 'unsafe-inline' 'strict-dynamic'; style-src 'self' https://fonts.googleapis.com https://heapanalytics.com https://cdn.hellosign.com 'unsafe-inline'; report-uri https://app.hellosign.com/csp_report; upgrade-insecure-requests
X-Dropbox-Request-Id
705cc168d460411ba2a95b3a69ffdd51
X-Dropbox-Response-Origin
far_remote
X-Ua-Compatible
IE=Edge
X-Webkit-Csp
base-uri 'none'; connect-src 'self' https://www.google-analytics.com https://heapanalytics.com https://api.sprig.com/sdk/ https://sentry.io https://d.dropbox.com https://ekr.zdassets.com https://hellosign.zendesk.com wss://hellosign.zendesk.com https://www.dropbox.com/amplitude_proxy/ingest_lenient; frame-ancestors 'self'; object-src 'none'; script-src https: 'report-sample' 'nonce-tMnvbLFF9/wsbDadw9ffWwO5' 'unsafe-inline' 'strict-dynamic'; style-src 'self' https://fonts.googleapis.com https://heapanalytics.com https://cdn.hellosign.com 'unsafe-inline'; report-uri https://app.hellosign.com/csp_report; upgrade-insecure-requests
date: Sun, 10 May 2026 01:20:17 GMT p3p: CP="NOP3PPOLICY" status: 404 Not Found x-content-security-policy: base-uri 'none'; connect-src 'self' https://www.google-analytics.com https://heapanalytics.com https://api.sprig.com/sdk/ https://sentry.io https://d.dropbox.com https://ekr.zdassets.com https://hellosign.zendesk.com wss://hellosign.zendesk.com https://www.dropbox.com/amplitude_proxy/ingest_lenient; frame-ancestors 'self'; object-src 'none'; script-src https: 'report-sample' 'nonce-tMnvbLFF9/wsbDadw9ffWwO5' 'unsafe-inline' 'strict-dynamic'; style-src 'self' https://fonts.googleapis.com https://heapanalytics.com https://cdn.hellosign.com 'unsafe-inline'; report-uri https://app.hellosign.com/csp_report; upgrade-insecure-requests x-dropbox-request-id: 705cc168d460411ba2a95b3a69ffdd51 x-dropbox-response-origin: far_remote x-ua-compatible: IE=Edge x-webkit-csp: base-uri 'none'; connect-src 'self' https://www.google-analytics.com https://heapanalytics.com https://api.sprig.com/sdk/ https://sentry.io https://d.dropbox.com https://ekr.zdassets.com https://hellosign.zendesk.com wss://hellosign.zendesk.com https://www.dropbox.com/amplitude_proxy/ingest_lenient; frame-ancestors 'self'; object-src 'none'; script-src https: 'report-sample' 'nonce-tMnvbLFF9/wsbDadw9ffWwO5' 'unsafe-inline' 'strict-dynamic'; style-src 'self' https://fonts.googleapis.com https://heapanalytics.com https://cdn.hellosign.com 'unsafe-inline'; report-uri https://app.hellosign.com/csp_report; upgrade-insecure-requests
Recommendations
Enable compression (gzip/brotli) to improve performance