Open
Cached
·
just now
16
Headers
Detected Technologies from Headers
AWS CloudFront
Atlassian Jira
AWS
Amazon S3
Box
Cloudflare Stream
Font Awesome
Google Analytics
Google API JS Client
Google Fonts
Google Hosted Libraries
Google Search
Google Static File Front End
Google Tag Manager
Google Translate
Heap
HubSpot Forms
Mixpanel
Sentry
Microsoft SharePoint
Unsplash
Vimeo
Weglot
YouTube
Google Cloud
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000; IncludeSubDomains;
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Present
accelerometer=(), ambient-light-sensor=(), autoplay=(); +38 more
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
Performance Headers
Connection
close
Transfer-Encoding
chunked
Vary
Accept-Encoding
connection: close transfer-encoding: chunked vary: Accept-Encoding
Caching Headers
Cache-Control
no-cache, no-store
cache-control: no-cache, no-store
Content Headers
Content-Type
text/html; charset=UTF-8
content-type: text/html; charset=UTF-8
Server Headers
Server
server:
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Date
Sat, 25 Jul 2026 11:55:58 GMT
P3p
CP="brightidea_is_not_a_potato"
X-Instance-Id
i-0e5d29f732c6ae686
date: Sat, 25 Jul 2026 11:55:58 GMT p3p: CP="brightidea_is_not_a_potato" x-instance-id: i-0e5d29f732c6ae686
Recommendations
Enable compression (gzip/brotli) to improve performance