Open
Cached
·
just now
23
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains
Content-Security-Policy
Basic
base-uri; font-src; form-action; +12 more
base-uri 'none'; font-src 'self' https://fonts.gstatic.com/s/inter/ https://*.gstatic.com data:; form-action 'self' https://*.phrase.com https://*.zendesk.com; frame-ancestors 'none'; img-src data: blob: 'self' https://gravatar.com/avatar/ https://*.userpilot.io *; object-src 'none'; script-src-attr 'none'; style-src 'self' https://fonts.googleapis.com/ https://*.userpilot.io https://fonts.gstatic.com https://fonts.googleapis.com https://*.birdie.so 'unsafe-inline' https://js.chargebee.com https://undefined.chargebee.com/assets/hp_v3/iframe_views/; script-src 'self' 'unsafe-eval' https://*.userpilot.io https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ http://js.userpilot.io/sdk/latest.js https://*.google.com https://*.googleadservices.com https://*.googletagmanager.com https://*.googleanalytics.com https://*.google-analytics.com https://cookie-cdn.cookiepro.com https://widget.intercom.io/ https://client.prod.mplat-ppcprotect.com https://js.zi-scripts.com/ https://googleads.g.doubleclick.net https://js.hs-scripts.com https://js.hs-banner.com https://js.hs-analytics.net https://*.hscollectedforms.net https://*.hubspot.com https://*.forethought.ai https://phrase.com https://*.licdn.com https://*.bing.com https://*.ads-twitter.com https://*.facebook.net https://*.albacross.com https://*.birdie.so 'unsafe-inline' https://js.chargebee.com https://js.chargebee.com/v2/chargebee.js; upgrade-insecure-requests; default-src 'self' 'unsafe-inline' 'unsafe-eval'; child-src 'self' *; frame-src https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/ https://undefined.chargebee.com/ 'self' *; worker-src 'self' blob:; connect-src 'self' https://*.userpilot.io wss://*.userpilot.io https://cookie-cdn.cookiepro.com https://js.chargebee.com https://js.hs-scripts.com https://widget.intercom.io https://snap.licdn.com https://bat.bing.com https://connect.facebook.net https://*.hscollectedforms.net https://privacyportal.cookiepro.com/request/v1/consentreceipts https://geolocation.onetrust.com/cookieconsentpub/v1/geo/location https://region1.google-analytics.com https://www.google-analytics.com https://www.google.com https://*.hubspot.com https://*.birdie.so wss://sock.birdie.so https://googleads.g.doubleclick.net ws: https://*.forethought.ai;
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
no-referrer
Permissions-Policy
Present
camera=(), display-capture=(), fullscreen=(), geolocation=(), microphone=()
Recommendations
- • Consider adding 'preload' to HSTS for maximum security
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
Performance Headers
1 headers
Connection
Performance
close
Caching Headers
3 headers
Cache-Control
Caching
no-cache, no-store
Expires
Caching
0
Pragma
Caching
no-cache
Content Headers
2 headers
Content-Length
Content
280637
Content-Type
Content
text/html;charset=utf-8
Server Headers
0 headers
No server headers found
CORS Headers
1 headers
Access-Control-Allow-Origin
Cors
*
Cookies Headers
1 headers
Set-Cookie
Cookies
idmsidebar=open; Path=/; Secure; SameSite=Lax; Secure
Other Headers
5 headers
Date
Other
Tue, 13 Jan 2026 19:53:24 GMT
Origin-Agent-Cluster
Other
?1
X-Dns-Prefetch-Control
Other
off
X-Download-Options
Other
noopen
X-Permitted-Cross-Domain-Policies
Other
none
Recommendations
Enable compression (gzip/brotli) to improve performance