Open
Cached
·
just now
18
Headers
Detected Technologies from Headers
YouTube
Google AdSense
Dreamdata
IPinfo
HubSpot Video
Google Tag Manager
Bing
Spotify
Reddit
HubSpot Forms
Cookiebot
Capterra
Google DoubleClick
Arcade
Google Analytics
ClickCease
Microsoft Advertising
Report URI
Next.js
Apple Podcasts
Google API JS Client
Google Fonts
Wistia
LinkedIn
Google Search
Facebook
Amazon S3
HubSpot
Strapi
Quora
Microsoft Clarity
jsDelivr
Google Cloud Storage
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Strengthen CSP by removing 'unsafe-eval'
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
Transfer-Encoding
chunked
Vary
RSC, Next-Router-State-Tree, Next-Router-Prefetch, Accept-Encoding
connection: close transfer-encoding: chunked vary: RSC, Next-Router-State-Tree, Next-Router-Prefetch, Accept-Encoding
Caching Headers
Cache-Control
private, no-cache, no-store, max-age=0, must-revalidate
cache-control: private, no-cache, no-store, max-age=0, must-revalidate
Content Headers
Content-Type
text/html; charset=utf-8
content-type: text/html; charset=utf-8
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Date
Mon, 04 May 2026 10:04:16 GMT
Link
rel=alternate
hreflang=en
rel=alternate
hreflang=es
rel=alternate
hreflang=pt
rel=alternate
hreflang=x-default
rel=alternate
hreflang=en
rel=alternate
hreflang=es
rel=alternate
hreflang=pt
rel=alternate
hreflang=x-default
URL
/_next/static/media/30d74baa196fe88a-s.p.woff2
rel=preload
as=font
crossorigin
type=font/woff2
URL
/_next/static/media/e4af272ccee01ff0-s.p.woff2
rel=preload
as=font
crossorigin
type=font/woff2
X-Accel-Buffering
no
X-Base-Url
https://ip-10-0-87-14.ec2.internal:8080
X-Current-Pathname
/
X-Dark-Mode
true
X-Double-Menu
false
X-Middleware-Rewrite
/en
X-Nonce
NTliM2M3NGUtMzA4Ny00MTc1LWE5ZmYtY2E0YTUzZTU5MDZj
date: Mon, 04 May 2026 10:04:16 GMT link: <https://invgate.com/>; rel="alternate"; hreflang="en", <https://invgate.com/es>; rel="alternate"; hreflang="es", <https://invgate.com/pt>; rel="alternate"; hreflang="pt", <https://invgate.com/>; rel="alternate"; hreflang="x-default", </_next/static/media/30d74baa196fe88a-s.p.woff2>; rel=preload; as="font"; crossorigin=""; type="font/woff2", </_next/static/media/e4af272ccee01ff0-s.p.woff2>; rel=preload; as="font"; crossorigin=""; type="font/woff2" x-accel-buffering: no x-base-url: https://ip-10-0-87-14.ec2.internal:8080 x-current-pathname: / x-dark-mode: true x-double-menu: false x-middleware-rewrite: /en x-nonce: NTliM2M3NGUtMzA4Ny00MTc1LWE5ZmYtY2E0YTUzZTU5MDZj
Recommendations
Enable compression (gzip/brotli) to improve performance
Consider removing X-Powered-By header to hide server technology