Open
Cached
·
just now
14
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains
Content-Security-Policy
Good
form-action; frame-ancestors; style-src; +2 more
form-action 'self' https://go.actionstep.com https://*.actionstep.com https://*.actionstepdev.com https://*.actionstepstaging.com; frame-ancestors 'self' https://*.microsoft.com https://*.actionstep.com https://*.officeapps.live.com https://*.office.com https://*.office365.com https://*.sharepoint.com https://*.affinipay.com; style-src 'nonce-actionstep' 'self' *.actionstep.com *.actionstepdev.com *.actionstepstaging.com; frame-src 'self' *.google.com *.actionstep.com *.actionstepdev.com *.actionstepstaging.com; default-src 'self' 'sha256-uWdRRopeDy933QHMx2w48mIYASka9opCnVnvysFrlcI=' 'sha256-KpJno/XhpVZ3LNZ7PrzAnVVVjnkhj1sPgz/fDxmq+2w=' 'sha256-Ys0QI3zsPrHG/jwsI/AqhUMN1DWSzpg2C+p6b9Rf50k=' 'sha256-BMP1rUsa1sA/fHm71aiQxkY4sr/ru5S0N9CFStP1xWA=' 'sha256-tg0I9AAWQLO0rrv6sepDjv5hJUmTq36zjiAS3sbeCsk=' 'sha256-W3EQrxRpIlHM+Ef+DeoRH+WAxefOALXsi7HAQmE4kKM=' 'nonce-actionstep' data: *.affinipay.com *.google-analytics.com *.licdn.com *.hotjar.com *.hs-scripts.com *.hs-banner.com *.facebook.net *.herokuapp.com https://fullstory.com *.fullstory.com *.hsforms.com *.usemessages.com *.adsymptotic.com *.intercomcdn.com *.hotjar.io *.hubapi.com *.ubembed.com *.intercom.io *.facebook.com *.hscollectedforms.net *.hs-analytics.net *.hubspot.com *.linkedin.com *.hsadspixel.net *.heapanalytics.com https://heapanalytics.com *.googletagmanager.com *.googleapis.com ajax.googleapis.com *.doubleclick.net *.googleadservices.com *.twitter.com t.co www.google.com *.google.co.nz *.gstatic.com apis.google.com analytics.google.com cdn.actionstep.com ct.capterra.com
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Missing
Not configured
Recommendations
- • Consider adding 'preload' to HSTS for maximum security
- • Strengthen CSP by removing 'unsafe-eval'
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Consider adding Permissions-Policy to control browser features
Performance Headers
2 headers
Connection
Performance
close
Transfer-Encoding
Performance
chunked
Caching Headers
3 headers
Cache-Control
Caching
no-store, no-cache, must-revalidate
Expires
Caching
Thu, 19 Nov 1981 08:52:00 GMT
Pragma
Caching
no-cache
Content Headers
1 headers
Content-Type
Content
text/html; charset=UTF-8
Server Headers
1 headers
Server
Server
nginx
CORS Headers
0 headers
No CORS headers found
Cookies Headers
1 headers
Set-Cookie
Cookies
st=78cs5a2kcjvo3ok6da0ihsuh80; path=/; domain=.actionstep.com; secure; HttpOnly; SameSite=None
Other Headers
1 headers
Date
Other
Sun, 25 Jan 2026 17:16:55 GMT
Recommendations
Enable compression (gzip/brotli) to improve performance