Open
Cached
·
just now
22
Headers
Detected Technologies from Headers
Apple ID
Apple Pay
Cloudflare CDN
Cloudflare CDNJS
Contentful
Crisp
Envoy
Facebook
Fingerprint
Forter
GeeTest
Google Analytics
Google API JS Client
Google Cloud Functions
Google DoubleClick
Google Fonts
Google Pay
Google Search
Google Static File Front End
Google Tag Manager
Greenhouse
jsDelivr
Next.js
Salesforce Cloud
Salesforce Sites
Taboola
TikTok Analytics
Twitter
YouTube
Google Cloud
HTTP Security Headers
Status
Strict-Transport-Security
Excellent
max-age=63072000; includeSubDomains; preload
X-Frame-Options
Present
ALLOW-FROM trade-hk-qa.osltest.com glb.osl.com www.osl.com glb.oslgroup.net
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Present
camera=(), geolocation=(), microphone=()
Recommendations
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
Performance Headers
Connection
close
Transfer-Encoding
chunked
Vary
RSC, Next-Router-State-Tree, Next-Router-Prefetch, Accept-Encoding
connection: close transfer-encoding: chunked vary: RSC, Next-Router-State-Tree, Next-Router-Prefetch, Accept-Encoding
Caching Headers
Cache-Control
public, max-age=60, stale-if-error=3600
Last-Modified
Fri, 01 May 2026 19:45:00 GMT
cache-control: public, max-age=60, stale-if-error=3600 last-modified: Fri, 01 May 2026 19:45:00 GMT
Content Headers
Content-Type
text/html; charset=utf-8
content-type: text/html; charset=utf-8
Server Headers
server: cloudflare x-powered-by: Next.js
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Date
Fri, 01 May 2026 19:45:00 GMT
Link
rel=alternate
hreflang=en
rel=alternate
hreflang=zh-Hans
rel=alternate
hreflang=zh-Hant
rel=alternate
hreflang=osl
rel=alternate
hreflang=en
rel=alternate
hreflang=zh-Hans
rel=alternate
hreflang=zh-Hant
rel=alternate
hreflang=osl
rel=alternate
hreflang=x-default
X-Middleware-Rewrite
/en
cf-cache-status: HIT cf-ray: 9f5148b8e980c978-IAD date: Fri, 01 May 2026 19:45:00 GMT link: <http://www-web-separation-glb.prod.osl-internal.com/en>; rel="alternate"; hreflang="en", <http://www-web-separation-glb.prod.osl-internal.com/zh-Hans>; rel="alternate"; hreflang="zh-Hans", <http://www-web-separation-glb.prod.osl-internal.com/zh-Hant>; rel="alternate"; hreflang="zh-Hant", <http://www-web-separation-glb.prod.osl-internal.com/osl>; rel="alternate"; hreflang="osl", <http://www-web-separation-glb.prod.osl-internal.com/>; rel="alternate"; hreflang="x-default" x-envoy-upstream-service-time: 173 x-middleware-rewrite: /en
Recommendations
Enable compression (gzip/brotli) to improve performance
Consider removing X-Powered-By header to hide server technology