Open
Cached
·
8h ago
21
Headers
Detected Technologies from Headers
Amplitude
Amazon S3
Bing
ClickCease
Cloudflare CDN
Cloudflare CDNJS
Cookiebot
CookieYes
Facebook
Font Awesome
Google AdSense
Google Analytics
Google API JS Client
Google DoubleClick
Google Search
Google Static File Front End
Google Tag Manager
HubSpot
HubSpot Analytics
HubSpot Forms
LinkedIn
Mouseflow
Reddit
Spotify
Vimeo
WP Engine
Yoast
YouTube
Google Cloud
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=10886400; includeSubDomains
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
Transfer-Encoding
chunked
Vary
Accept-Encoding, Accept-Encoding, Accept-Encoding, Accept-Encoding,Cookie
connection: close transfer-encoding: chunked vary: Accept-Encoding, Accept-Encoding, Accept-Encoding, Accept-Encoding,Cookie
Caching Headers
Age
288
Cache-Control
max-age=600, must-revalidate
Last-Modified
Sun, 26 Apr 2026 09:49:20 GMT
age: 288 cache-control: max-age=600, must-revalidate last-modified: Sun, 26 Apr 2026 09:49:20 GMT
Content Headers
Content-Type
text/html; charset=UTF-8
content-type: text/html; charset=UTF-8
Server Headers
server: cloudflare x-powered-by: WP Engine
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Alt-Svc
h3=":443"; ma=86400
Date
Sun, 26 Apr 2026 09:57:38 GMT
X-Cache
HIT: 1
X-Cache-Group
normal
X-Cacheable
SHORT
alt-svc: h3=":443"; ma=86400 cf-cache-status: HIT cf-ray: 9f24b972982b5d04-IAD date: Sun, 26 Apr 2026 09:57:38 GMT x-cache: HIT: 1 x-cache-group: normal x-cacheable: SHORT
Recommendations
Enable compression (gzip/brotli) to improve performance
Consider removing X-Powered-By header to hide server technology