Open
Cached
·
just now
21
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=15768000; includeSubDomains
Content-Security-Policy
Basic
base-uri; font-src; form-action; +8 more
base-uri self https://*.eye-able.com https://eye-able.com; font-src 'self' https: data:; form-action 'self' https://*.hubspot.com https://*.hsforms.com; frame-ancestors 'self' https://app.storyblok.com; img-src 'self' data: https://*.storyblok.com https://*.eye-able.com https://cloud.ccm19.de https://*.linkedin.com https://*.google.com https://*.google.de https://*.facebook.com https://*.facebook.net https://*.meta.com https://*.doubleclick.net https://*.googletagmanager.com https://*.googleadservices.com https://*.hubspot.com https://*.hsforms.com https://*.lfeeder.com https://*.bing.com; object-src 'none'; script-src-attr 'none'; style-src 'self' https: 'unsafe-inline'; script-src 'self' 'unsafe-inline' https://*.bing.com https://*.storyblok.com https://*.hotjar.com https://cdn.eye-able.com https://load.dt.eye-able.com https://cloud.ccm19.de https://cdn.weglot.com https://cdn-api-weglot.com https://*.googletagmanager.com https://stapecdn.com https://*.linkedin.com https://*.licdn.com https://*.google.com https://*.googleadservices.com https://*.googlesyndication.com https://*.facebook.com https://*.facebook.net https://*.meta.com https://*.doubleclick.net https://*.hs-scripts.com https://*.hsforms.com https://*.hsforms.net https://*.hs-analytics.net https://*.hsadspixel.net https://*.hscollectedforms.net https://*.hs-banner.com https://*.usemessages.com https://*.lfeeder.com https://*.posthog.com; upgrade-insecure-requests; connect-src 'self' https://dt.eye-able.com https://*.make.com https://*.storyblok.com https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com https://*.eye-able.com https://cloud.ccm19.de https://cdn.weglot.com https://cdn-api-weglot.com https://google.com https://*.google.com https://*.google.de https://*.googleadservices.com https://*.linkedin.com https://*.facebook.com https://*.facebook.net https://*.meta.com https://*.doubleclick.net https://*.hscollectedforms.net https://*.hubapi.com https://*.hsforms.com https://*.hsappstatic.net https://*.amazonaws.com https://*.hubapi.com https://*.hubspot.com https://*.bing.com https://*.posthog.com;
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
no-referrer
Permissions-Policy
Present
camera=(), display-capture=(), fullscreen=(), geolocation=(), microphone=()
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
Performance Headers
2 headers
Connection
Performance
close
Transfer-Encoding
Performance
chunked
Caching Headers
0 headers
No caching headers found
Content Headers
1 headers
Content-Type
Content
text/html;charset=utf-8
Server Headers
2 headers
Server
Server
nginx
X-Powered-By
Server
PleskLin
CORS Headers
1 headers
Access-Control-Allow-Origin
Cors
*
Cookies Headers
1 headers
Set-Cookie
Cookies
i18n_redirected=en; Path=/; Expires=Fri, 25 Dec 2026 18:13:21 GMT; SameSite=Lax
Other Headers
5 headers
Date
Other
Thu, 25 Dec 2025 18:13:21 GMT
Origin-Agent-Cluster
Other
?1
X-Dns-Prefetch-Control
Other
off
X-Download-Options
Other
noopen
X-Permitted-Cross-Domain-Policies
Other
none
Recommendations
Enable compression (gzip/brotli) to improve performance
Add Cache-Control header to optimize caching
Consider removing X-Powered-By header to hide server technology
Analysis completed in 1092ms