Open
Cached
·
just now
18
Headers
Detected Technologies from Headers
Adobe Target
AWS CloudFront
YouTube
Google AdSense
Quantum Metric
Criteo
Google Tag Manager
Bing
Heroku
Liveramp
Google DoubleClick
Crazy Egg
Cloudflare CDN
Loggly
Google Static File Front End
LaunchDarkly
Google API JS Client
AzureFrontDoor
Issuu
Contentful
Google Search
Cloudflare
Adobe Dynamic Tag Management
Facebook
Amazon S3
OneTrust
OpinionLab
Pinterest
Adobe Experience Manager
Upsellit
Vercel
jQuery
Akamai
Active incidents
The Trade Desk
Font Awesome
Google Cloud
Microsoft Azure
Google App Engine
HTTP Security Headers
Status
Strict-Transport-Security
Good
max-age=31536000 ; includeSubDomains
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Consider adding 'preload' to HSTS for maximum security
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
connection: close
Caching Headers
Cache-Control
max-age=1800
Expires
Wed, 19 Aug 2026 20:44:10 GMT
cache-control: max-age=1800 expires: Wed, 19 Aug 2026 20:44:10 GMT
Content Headers
Content-Length
396
Content-Type
text/html
content-length: 396 content-type: text/html
Server Headers
No server headers found
CORS Headers
Access-Control-Allow-Credentials
true
Access-Control-Allow-Methods
GET, POST, PUT, HEAD, DELETE, OPTIONS, PATCH
access-control-allow-credentials: true access-control-allow-methods: GET, POST, PUT, HEAD, DELETE, OPTIONS, PATCH
Cookies Headers
Other Headers
Allow
GET, POST, PUT, HEAD, DELETE, OPTIONS, PATCH
Date
Wed, 19 Aug 2026 20:14:10 GMT
Mime-Version
1.0
Server-Timing
cdn-cache; desc=HIT, edge; dur=1, ak_p; desc="1787170450518_400321304_1073620934_21_30664_102_401_-";dur=1
X-Req
a=a;c=www.cvs.com-shop_plp,www.cvs.com-shop;d=desktop;g=0.186bdc17.1787170450.3ffe27c6;h=www.cvs.com;i=23.220.107.24;l=use;t=ut;u=brw
allow: GET, POST, PUT, HEAD, DELETE, OPTIONS, PATCH date: Wed, 19 Aug 2026 20:14:10 GMT mime-version: 1.0 server-timing: cdn-cache; desc=HIT, edge; dur=1, ak_p; desc="1787170450518_400321304_1073620934_21_30664_102_401_-";dur=1 x-req: a=a;c=www.cvs.com-shop_plp,www.cvs.com-shop;d=desktop;g=0.186bdc17.1787170450.3ffe27c6;h=www.cvs.com;i=23.220.107.24;l=use;t=ut;u=brw
Recommendations
Enable compression (gzip/brotli) to improve performance