Open
Cached
·
just now
22
Headers
Detected Technologies from Headers
YouTube
Google AdSense
Google Tag Manager
Bing
Salesforce Cloud
SurveyMonkey
Ahrefs
AppNexus (Xandr)
HubSpot Forms
JotForm
Fonts.com
Google DoubleClick
Google Analytics
Microsoft Advertising
Pusher
6sense
Cloudflare CDN
Active incidents
Google Static File Front End
Next.js
Google API JS Client
Algolia
LinkedIn
HubSpot CMS
ZoomInfo
Cloudinary
HubSpot Analytics
Mapbox
Google Search
Facebook
OneTrust
Vercel
Simplecast
Salesforce Pardot
Vimeo
HubSpot
Microsoft Clarity
HubSpot Live Chat
jsDelivr
Google Cloud
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=15552000
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
Transfer-Encoding
chunked
Vary
rsc, next-router-state-tree, next-router-prefetch, next-router-segment-prefetch, accept-encoding
connection: close transfer-encoding: chunked vary: rsc, next-router-state-tree, next-router-prefetch, next-router-segment-prefetch, accept-encoding
Caching Headers
Age
11136
Cache-Control
public, max-age=0, must-revalidate
age: 11136 cache-control: public, max-age=0, must-revalidate
Content Headers
Content-Type
text/html; charset=utf-8
content-type: text/html; charset=utf-8
Server Headers
server: cloudflare x-powered-by: Next.js
CORS Headers
Access-Control-Allow-Origin
https://cms.crisis24.com
access-control-allow-origin: https://cms.crisis24.com
Cookies Headers
Other Headers
Alt-Svc
h3=":443"; ma=86400
Date
Mon, 11 May 2026 09:31:56 GMT
X-Matched-Path
/en
alt-svc: h3=":443"; ma=86400 cf-cache-status: DYNAMIC cf-ray: 9fa02c6fae995042-IAD date: Mon, 11 May 2026 09:31:56 GMT x-matched-path: /en x-nextjs-prerender: 1 x-nextjs-stale-time: 300 x-vercel-cache: HIT x-vercel-id: iad1::pdx1::6cq8k-1778491916757-c548c1b59bed
Recommendations
Enable compression (gzip/brotli) to improve performance
Consider removing X-Powered-By header to hide server technology