Open
Cached
·
just now
20
Headers
Detected Technologies from Headers
Bing
Microsoft Advertising
Cloudflare CDN
Facebook
Google Analytics
Google Cloud Run
Google DoubleClick
Google Fonts
Google Search
Google Static File Front End
Google Tag Manager
Hotjar
HubSpot
HubSpot Analytics
HubSpot CMS
HubSpot Forms
HubSpot Live Chat
LinkedIn
Reddit
Sentry
unpkg
Visual Website Optimizer
Wistia
WP Engine
YouTube
Zapier
Google Cloud
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Present
private-state-token-redemption=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com"), private-state-token-issuance=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com")
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
Performance Headers
Connection
close
Transfer-Encoding
chunked
Vary
Accept-Encoding, Accept-Encoding, Accept-Encoding, Accept-Encoding,Cookie
connection: close transfer-encoding: chunked vary: Accept-Encoding, Accept-Encoding, Accept-Encoding, Accept-Encoding,Cookie
Caching Headers
Cache-Control
max-age=600, must-revalidate
cache-control: max-age=600, must-revalidate
Content Headers
Content-Type
text/html; charset=UTF-8
content-type: text/html; charset=UTF-8
Server Headers
server: cloudflare x-powered-by: WP Engine
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Alt-Svc
h3=":443"; ma=86400
Date
Thu, 30 Apr 2026 22:23:31 GMT
X-Cache
HIT: 3
X-Cache-Group
normal
X-Cacheable
SHORT
alt-svc: h3=":443"; ma=86400 cf-cache-status: DYNAMIC cf-ray: 9f49f38c7c5ae619-IAD date: Thu, 30 Apr 2026 22:23:31 GMT link: <https://opensrs.com/>; rel=shortlink x-cache: HIT: 3 x-cache-group: normal x-cacheable: SHORT
Recommendations
Enable compression (gzip/brotli) to improve performance
Consider removing X-Powered-By header to hide server technology