Open
Cached
·
just now
24
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains
Content-Security-Policy
Basic
default-src; object-src; frame-ancestors; +9 more
default-src 'self' 'unsafe-eval' 'unsafe-inline' blob: data:; object-src 'none'; frame-ancestors 'self'; connect-src 'self' * https://*.productfruits.com wss://*.productfruits.com https://productfruits.help/; font-src 'self' 'unsafe-inline' data: https://k.clarity.ms https://www.google.ca https://www.google.com.pe www.gstatic.com fonts.gstatic.com optimize.google.com https://t.co https://analytics.twitter.com https://fonts.googleapis.com https://www.googletagmanager.com https://static.ads-twitter.com https://px.ads.linkedin.com https://www.googleoptimize.com https://*.cdntwrk.com https://*.genetec.com https://static.cloudflareinsights.com https://cdn.livechatinc.com https://oc-cdn-public.azureedge.net https://*.wrike.com https://*.navattic.com https://storage.googleapis.com; frame-src 'self' https://k.clarity.ms https://www.google.ca https://www.google.com.pe https://bid.g.doubleclick.net www.gstatic.com fonts.gstatic.com optimize.google.com https://t.co https://analytics.twitter.com https://fonts.googleapis.com https://www.googletagmanager.com https://static.ads-twitter.com https://px.ads.linkedin.com https://www.googleoptimize.com https://*.addthis.com https://*.bloomreach.cloud https://*.doubleclick.net https://*.facebook.com https://*.genetec.com https://*.geneteccloud.com https://*.google.com https://*.livechatinc.com https://*.marketo.com https://*.podbean.com https://*.powerappsportals.com https://*.youtube.com https://static.addtoany.com https://oc-cdn-public.azureedge.net genetec.involve.me https://*.wrike.com https://*.navattic.com https://storage.googleapis.com https://*.productfruits.com https://*.vidyard.com; img-src 'self' 'unsafe-inline' data: * https://*.productfruits.com; media-src 'self' https://k.clarity.ms https://www.google.ca https://www.google.com.pe www.gstatic.com fonts.gstatic.com optimize.google.com https://t.co https://analytics.twitter.com https://fonts.googleapis.com https://www.googletagmanager.com https://static.ads-twitter.com https://px.ads.linkedin.com https://www.googleoptimize.com https://*.bloomreach.cloud https://*.genetec.com https://*.widencdn.net https://*.youtube.com https://genetec.widen.net https://youtu.be https://static.cloudflareinsights.com; script-src-elem 'self' 'unsafe-eval' 'unsafe-inline' blob: https://k.clarity.ms https://www.google.ca https://www.google.com.pe www.gstatic.com fonts.gstatic.com optimize.google.com https://t.co https://analytics.twitter.com https://fonts.googleapis.com https://www.googletagmanager.com https://static.ads-twitter.com https://px.ads.linkedin.com https://www.googleoptimize.com https://*.addthis.com https://*.bing.com https://*.bloomreach.cloud https://*.cdntwrk.com https://*.clarity.ms https://*.cookielaw.org https://*.crazyegg.com https://*.doubleclick.net https://*.facebook.net https://*.genetec.com https://*.google-analytics.com https://*.google.com https://*.googleadservices.com https://*.googleoptimize.com https://*.googletagmanager.com https://*.gstatic.com https://*.inspectlet.com https://*.licdn.com https://*.livechatinc.com https://*.marketo.com https://*.marketo.net https://*.onetrust.com https://*.site24x7rum.com https://*.widencdn.net https://*.youtube.com https://genetec.widen.net https://ionfiles.scribblecdn.net https://v1.addthisedge.com https://youtu.be https://z.moatads.com https://static.cloudflareinsights.com https://static.addtoany.com https://dev.visualwebsiteoptimizer.com https://app.vwo.com https://oc-cdn-public.azureedge.net https://www.redditstatic.com genetec.involve.me ajax.googleapis.com https://maps.googleapis.com https://js.navattic.com https://*.productfruits.com https://*.zoominfo.com https://js.zi-scripts.com https://*.vidyard.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' blob: https://k.clarity.ms https://www.google.ca https://www.google.com.pe https://tagmanager.google.com https://googleads.g.doubleclick.net https://www.googleadservices.com https://www.google.com https://www.google-analytics.com https://ssl.google-analytics.com www.gstatic.com fonts.gstatic.com optimize.google.com https://t.co https://analytics.twitter.com https://fonts.googleapis.com https://www.googletagmanager.com https://static.ads-twitter.com https://px.ads.linkedin.com https://www.googleoptimize.com https://*.addthis.com https://*.bing.com https://*.bloomreach.cloud https://*.cdntwrk.com https://*.clarity.ms https://*.cookielaw.org https://*.crazyegg.com https://*.doubleclick.net https://*.facebook.net https://*.genetec.com https://*.google-analytics.com https://*.google.com https://*.googleadservices.com https://*.googleoptimize.com https://*.googletagmanager.com https://*.gstatic.com https://*.inspectlet.com https://*.licdn.com https://*.livechatinc.com https://*.marketo.com https://*.marketo.net https://*.onetrust.com https://*.site24x7rum.com https://*.widencdn.net https://*.youtube.com https://genetec.widen.net https://ionfiles.scribblecdn.net https://v1.addthisedge.com https://youtu.be https://z.moatads.com https://static.cloudflareinsights.com https://oc-cdn-public.azureedge.net https://*.wrike.com https://*.navattic.com https://storage.googleapis.com https://*.productfruits.com https://*.zoominfo.com https://js.zi-scripts.com https://*.vidyard.com; style-src 'self' 'unsafe-inline' https://k.clarity.ms https://www.google.ca https://www.google.com.pe https://tagmanager.google.com www.gstatic.com fonts.gstatic.com optimize.google.com https://t.co https://analytics.twitter.com https://fonts.googleapis.com https://www.googletagmanager.com https://static.ads-twitter.com https://px.ads.linkedin.com https://www.googleoptimize.com https://*.bloomreach.cloud https://*.cdntwrk.com https://*.genetec.com https://*.marketo.com https://static.cloudflareinsights.com https://oc-cdn-public.azureedge.net https://*.wrike.com https://*.navattic.com https://storage.googleapis.com https://*.productfruits.com https://*.vidyard.com; style-src-elem 'self' 'unsafe-inline' https://k.clarity.ms https://www.google.ca https://www.google.com.pe https://tagmanager.google.com www.gstatic.com fonts.gstatic.com optimize.google.com https://t.co https://analytics.twitter.com https://fonts.googleapis.com https://www.googletagmanager.com https://static.ads-twitter.com https://px.ads.linkedin.com https://www.googleoptimize.com https://*.bloomreach.cloud https://*.cdntwrk.com https://*.genetec.com https://*.marketo.com https://static.cloudflareinsights.com https://oc-cdn-public.azureedge.net https://*.wrike.com https://*.navattic.com https://storage.googleapis.com https://*.productfruits.com https://*.vidyard.com
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Present
accelerometer=(), ambient-light-sensor=(), autoplay=(self), battery=(), camera=(), encrypted-media=(), fullscreen=(), geolocation=(self), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), usb=(), xr-spatial-tracking=()
Recommendations
- • Consider adding 'preload' to HSTS for maximum security
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
Performance Headers
3 headers
Connection
Performance
close
Transfer-Encoding
Performance
chunked
Vary
Performance
Origin, accept-encoding
Caching Headers
5 headers
Age
Caching
44916
Cache-Control
Caching
public, max-age=1800
Expires
Caching
Fri, 30 Jan 2026 08:42:14 GMT
Last-Modified
Caching
Thu, 29 Jan 2026 19:43:38 GMT
Pragma
Caching
no-cache
Content Headers
1 headers
Content-Type
Content
text/html;charset=UTF-8
Server Headers
1 headers
Server
Server
cloudflare
CORS Headers
2 headers
Access-Control-Allow-Credentials
Cors
true
Access-Control-Allow-Origin
Cors
*
Cookies Headers
1 headers
Set-Cookie
Cookies
__cf_bm=0nlIoDUEiNsMXbzDOxXVwaBu5ln7SDBpCZeKhgWXLm8-1769760734.62734-1.0.1.1-SMrWeyc_WM7XBV1n3v4uhrqj2BboErCXyJPo6i6AuuEjWUWSvI3OiE_Hz3C5rtcN.CTgTN3F7UbYBmAq9UDbqccL8WXfg8dEXXJn7wEGWa5.1U0_v6J7_ANdpuI48KOr; HttpOnly; Secure; Path=/; Domain=genetec.com; Expires=Fri, 30 Jan 2026 08:42:14 GMT
Other Headers
4 headers
Cf-Cache-Status
Other
HIT
Cf-Ray
Other
9c5f80cf68692003-IAD
Date
Other
Fri, 30 Jan 2026 08:12:14 GMT
Server-Timing
Other
cfEdge;dur=30,cfOrigin;dur=0
Recommendations
Enable compression (gzip/brotli) to improve performance