Open
Cached
·
just now
20
Headers
Detected Technologies from Headers
AWS CloudFront
Google Tag Manager
Bing
Google reCAPTCHA
Fullstory
Reddit
HubSpot Forms
HubSpot Feedback & Surveys
Google DoubleClick
Google Analytics
Segment
New Relic
Google Static File Front End
Google API JS Client
TikTok Analytics
Google Fonts
Clickagy
Wistia
Algolia
LinkedIn
Zendesk
Contentful
ZoomInfo
HubSpot Analytics
Google Search
Facebook
Pinterest
HubSpot
YouTube
The Trade Desk
Microsoft Clarity
Sentry
jsDelivr
Google Cloud
HTTP Security Headers
Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains
X-Frame-Options
Good
sameorigin
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Present
origin-when-cross-origin
Permissions-Policy
Missing
Not configured
Recommendations
- • Consider adding 'preload' to HSTS for maximum security
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
Vary
Accept-Encoding
connection: close vary: Accept-Encoding
Caching Headers
Age
1340
Cache-Control
public,max-age=3609
age: 1340 cache-control: public,max-age=3609
Content Headers
Content-Length
333754
Content-Type
text/html; charset=utf-8
content-length: 333754 content-type: text/html; charset=utf-8
Server Headers
server: CloudFront x-powered-by: MYOB
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Alt-Svc
h3=":443"; ma=86400
Date
Thu, 09 Apr 2026 22:08:17 GMT
alt-svc: h3=":443"; ma=86400 date: Thu, 09 Apr 2026 22:08:17 GMT via: 1.1 2129e94e52a290c5a20327b4f257b076.cloudfront.net (CloudFront) x-amz-cf-id: 8BKdYSU3qeep-VDy2M4eX4gwI_MCNbSQ_fx0CF4umsbrom6AWuFrdg== x-amz-cf-pop: IAD61-P8 x-cache: Hit from cloudfront
Recommendations
Enable compression (gzip/brotli) to improve performance
Consider removing X-Powered-By header to hide server technology