Open
Cached
·
just now
20
Headers
Detected Technologies from Headers
AWS CloudFront
Google AdSense
Chili Piper
Dreamdata
Google Tag Manager
WP Engine
Bugsnag
G2
Spotify
SalesLoft
AppNexus (Xandr)
Active incidents
OpenX
Yahoo
Liveramp
HubSpot Forms
Capterra
JotForm
Advertising.com
Google DoubleClick
AdRoll
Google Analytics
ClearBit
Yoast
6sense
Cloudflare CDN
Basis Technologies
Google Static File Front End
Outbrain
Google Fonts
Vidyard
Clickagy
Twitter
Hotjar
LinkedIn
PubMatic
HubSpot CMS
ZoomInfo
HubSpot Analytics
TrustRadius
Google Search
Adobe Marketo
Demandbase
Facebook
Amazon S3
bunny.net
AddEvent
TripleLift
DigitalOcean Spaces
Influitive
Taboola
Google Optimize
HubSpot
Intercom
Font Awesome
HubSpot Live Chat
jsDelivr
Google Cloud
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=63072000
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Present
private-state-token-redemption=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com"), private-state-token-issuance=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com")
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
Performance Headers
Connection
close
Transfer-Encoding
chunked
Vary
Accept-Encoding, Accept-Encoding, Accept-Encoding, Accept-Encoding,Cookie
connection: close transfer-encoding: chunked vary: Accept-Encoding, Accept-Encoding, Accept-Encoding, Accept-Encoding,Cookie
Caching Headers
Cache-Control
max-age=600, must-revalidate
cache-control: max-age=600, must-revalidate
Content Headers
Content-Type
text/html; charset=UTF-8
content-type: text/html; charset=UTF-8
Server Headers
server: cloudflare x-powered-by: WP Engine
CORS Headers
Access-Control-Allow-Origin
*
access-control-allow-origin: *
Cookies Headers
Other Headers
Alt-Svc
h3=":443"; ma=86400
Date
Tue, 28 Apr 2026 12:16:16 GMT
X-Cache
HIT: 12
X-Cache-Group
normal
X-Cacheable
SHORT
alt-svc: h3=":443"; ma=86400 cf-cache-status: DYNAMIC cf-ray: 9f35ff446f91c999-IAD date: Tue, 28 Apr 2026 12:16:16 GMT x-cache: HIT: 12 x-cache-group: normal x-cacheable: SHORT
Recommendations
Enable compression (gzip/brotli) to improve performance
Consider removing X-Powered-By header to hide server technology