Open
Cached
·
just now
20
Headers
Detected Technologies from Headers
Adobe Marketo
Amplitude
Microsoft Advertising
Bizzabo
Builder.io
ClearBit
Didomi
G2
Google AdSense
Google Analytics
Google DoubleClick
Google Fonts
Google Search
Google Tag Manager
LinkedIn
Navattic
Next.js
OneTrust
Qualified
Segment
Sentry
6sense
Storylane
Vercel
Wistia
YouTube
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=63072000
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Accept-Ranges
bytes
Connection
close
Vary
rsc, next-router-state-tree, next-router-prefetch, next-router-segment-prefetch
accept-ranges: bytes connection: close vary: rsc, next-router-state-tree, next-router-prefetch, next-router-segment-prefetch
Caching Headers
Age
40458
Cache-Control
public, max-age=0, must-revalidate
Etag
"38991772498452a68f719716dc97020a"
age: 40458 cache-control: public, max-age=0, must-revalidate etag: "38991772498452a68f719716dc97020a"
Content Headers
Content-Disposition
inline
Content-Length
532933
Content-Type
text/html; charset=utf-8
content-disposition: inline content-length: 532933 content-type: text/html; charset=utf-8
CORS Headers
Access-Control-Allow-Origin
*
access-control-allow-origin: *
Cookies Headers
Other Headers
Date
Fri, 10 Apr 2026 08:50:11 GMT
Reporting-Endpoints
csp-endpoint="https://browser-intake-us3-datadoghq.com/api/v2/logs?dd-api-key=undefined&dd-evp-origin=content-security-policy&ddsource=csp-report"
X-Matched-Path
/
date: Fri, 10 Apr 2026 08:50:11 GMT reporting-endpoints: csp-endpoint="https://browser-intake-us3-datadoghq.com/api/v2/logs?dd-api-key=undefined&dd-evp-origin=content-security-policy&ddsource=csp-report" x-matched-path: / x-nextjs-prerender: 1 x-nextjs-stale-time: 300 x-vercel-cache: HIT x-vercel-id: iad1::qrgl5-1775811011132-5007fe0c8a27
Recommendations
Enable compression (gzip/brotli) to improve performance