Open
Cached
·
just now
23
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000
Content-Security-Policy
Basic
base-uri; default-src; frame-ancestors; +6 more
base-uri 'self'; default-src 'self' 'nonce-25a779824ea3afb7a1035f53abc31914' https://cdn.shopify.com https://shopify.com; frame-ancestors 'none'; style-src 'self' https://fonts.googleapis.com https://fonts.gstatic.com https://use.typekit.net https://p.typekit.net https://*.livechatinc.com https://*.klarnacdn.net https://*.acsbapp.com https://*.hubspot.com https://*.hsappstatic.net https://cdn.cookie-script.com 'self' 'unsafe-inline' https://cdn.shopify.com; connect-src pivotcyclescms.wpenginepowered.com https://cms.pivotcycles.com https://cdn.shopify.com https://unpkg.com https://cdn.jsdelivr.net https://*.affirm.com https://prodregistryv2.org:* https://featureassets.org:* https://*.locally.com https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://www.facebook.com https://connect.facebook.net https://*.clarity.ms https://api.livechatinc.com wss://lc.chat https://j.clarity.ms https://*.clarity.ms https://www.facebook.com https://connect.facebook.net https://www.googleadservices.com https://googleads.g.doubleclick.net https://pagead2.googlesyndication.com https://*.klarna.com https://*.klarnacdn.net https://*.klarnaservices.com https://*.klarnaevt.com https://acsbapp.com https://cdn.acsbapp.com https://*.acsbapp.com https://*.hubspot.com https://*.hubapi.com https://*.hsappstatic.net https://*.hscollectedforms.net https://*.hsforms.com https://js.hs-scripts.com https://js.usemessages.com https://d1jiq9n77635tp.cloudfront.net:* https://5raer21h.apicdn.sanity.io:* https://o4509125266702336.ingest.us.sentry.io:* https://www.googleapis.com:* https://ground-keeper-custom.myshopify.com:* https://ka8jjo2110.execute-api.us-east-1.amazonaws.com:* https://js.hs-banner.com https://*.hs-banner.com https://*.sentry.io https://*.ingest.sentry.io https://cdn.cookie-script.com https://report.cookie-script.com https://consent.cookie-script.com 'self' https://cdn.shopify.com/ https://monorail-edge.shopifysvc.com https://pivotcycles.myshopify.com https://pivotcycles.myshopify.com; script-src 'self' 'unsafe-eval' 'wasm-unsafe-eval' 'strict-dynamic' 'sha256-3bzWVxQE32IZQKH9eh8KzyHuhXOlMrboDVVBRd0fWTU=' https://cdn.shopify.com:* https://cdn1.affirm.com https://*.locally.com https://gkc-script-server.pages.dev https://ajax.cloudflare.com https://cloudflareinsights.com https://static.cloudflareinsights.com https://www.googletagmanager.com https://tagmanager.google.com https://cdn.livechatinc.com https://*.klarna.com https://*.klarnacdn.net https://acsbapp.com https://*.acsbapp.com https://*.hubspot.com https://*.hsforms.net https://*.hsappstatic.net https://js.usemessages.com https://js.hs-scripts.com https://js.hs-banner.com https://cdn.cookie-script.com https://report.cookie-script.com 'nonce-25a779824ea3afb7a1035f53abc31914'; frame-src *.youtube.com https://open.spotify.com https://cms.pivotcycles.com https://www.affirm.com https://*.locally.com https://gkc-script-server.pages.dev https://www.googletagmanager.com https://cdn.livechatinc.com https://secure.livechatinc.com https://*.livechatinc.com https://*.klarna.com https://*.klarnaservices.com https://www.facebook.com https://acsbapp.com https://*.acsbapp.com https://*.hubspot.com https://*.hsforms.com https://*.hsappstatic.net; img-src self *.pivotcycles.com vern.ngrok.app anthony.ngrok.app pivotcyclescms.wpenginepowered.com https://needed-absolute-mule.ngrok-free.app https://oyster-refined-rodent.ngrok-free.app https://pleasant-woodcock-upright.ngrok-free.app https://civil-redfish-real.ngrok-free.app https://anthony.pivotcycles.com https://anthony.ngrok.app http://localhost:3000 *.wpenginepowered.com cdn.shopify.com *.buzzsprout.com https://cdn-assets.affirm.com:* https://media2.locally.com picsum.photos *.picsum.photos blob: data: *.pivotcycles.com pivotcyclescms.wpenginepowered.com cdn.shopify.com *.buzzsprout.com https://res.cloudinary.com https://*.affirm.com https://*.locally.com https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://pagead2.googlesyndication.com https://*.facebook.com https://connect.facebook.net https://*.clarity.ms https://c.bing.com:* https://*.livechatinc.com https://cdn.files-text.com https://*.klarna.com https://*.klarnacdn.net https://*.acsbapp.com https://*.hubspot.com https://*.hsforms.com https://*.hsappstatic.net https://*.hsforms.com https://d1jiq9n77635tp.cloudfront.net https://cdn.cookie-script.com; font-src 'self' data: https://cdn.shopify.com https://fonts.gstatic.com https://use.typekit.net https://p.typekit.net https://*.klarnacdn.net
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
2 headers
Connection
Performance
close
Transfer-Encoding
Performance
chunked
Caching Headers
1 headers
Cache-Control
Caching
public, max-age=300, s-maxage=3600, stale-while-revalidate=86400
Content Headers
1 headers
Content-Type
Content
text/html
Server Headers
1 headers
Server
Server
cloudflare
CORS Headers
0 headers
No CORS headers found
Cookies Headers
0 headers
No cookies headers found
Other Headers
14 headers
Accept-Ch
Other
Sec-CH-Viewport-Width, Sec-CH-DPR, Sec-CH-Width
Alt-Svc
Other
h3=":443"; ma=86400
Cf-Ray
Other
9c2ab77c3b2337a2-IAD
Critical-Ch
Other
Sec-CH-DPR, Sec-CH-Width
Date
Other
Fri, 23 Jan 2026 22:27:09 GMT
Nel
Other
{"success_fraction":0.01,"report_to":"cf-nel","max_age":604800}
Oxygen-Full-Page-Cache
Other
uncacheable
Powered-By
Other
Shopify, Oxygen, Hydrogen
Report-To
Other
{"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=yqY3VOhqXtGxdudHkvJGmAOdhNBWeG%2FuOGqDzgXDMUrA2d3WEEoW%2BTAa4YJ7lr9SOeDiaeYrK2NGZEUf6nOxF7siqfMGVkuL%2BDDL69d6V0%2B%2FDKS0VsgMv0ruiejHDInnAE40Xc4%3D"}],"group":"cf-nel","max_age":604800}
Server-Timing
Other
cfRequestDuration;dur=284.999847
X-Download-Options
Other
noopen
X-Permitted-Cross-Domain-Policies
Other
none
X-Request-Id
Other
d0112f80-db24-4f6c-ba35-6114bc897244-1769207228
X-Shopid
Other
57679544474
Recommendations
Enable compression (gzip/brotli) to improve performance