Cached · just now
17 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31536000; includeSubdomains
Content-Security-Policy
Basic
script-src; style-src; img-src; +4 more
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Improve CSP by adding more specific directives and removing 'unsafe-inline'
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

Performance Headers

2 headers
Connection
Performance
close
Transfer-Encoding
Performance
chunked

Caching Headers

3 headers
Cache-Control
Caching
private
Expires
Caching
Thu, 01 Jan 1970 00:00:00 GMT
Pragma
Caching
no-cache

Content Headers

1 headers
Content-Type
Content
text/html;charset=ISO-8859-1

Server Headers

2 headers
Server
Server
cloudflare
X-Powered-By
Server
JSP/3.1

CORS Headers

0 headers
No CORS headers found

Cookies Headers

1 headers
Set-Cookie
Cookies
px-current-merchant-id=2; path=/; domain=pxsweb.com; secure

Other Headers

5 headers
Cf-Cache-Status
Other
DYNAMIC
Cf-Ray
Other
9cc8d9a0bfcc093a-IAD
Content-Security-Policy-Report-Only
Other
connect-src 'self' *.px-cloud.net *.perimeterx.net *.px-cdn.net *.pxchk.net *.px-client.net https://*.api.sanity.io https://apple-pay-gateway-cert.apple.com/paymentservices/startSession https://core.spreedly.com/v1/payment_methods.json https://edge.fullstory.com https://rs.fullstory.com https://cdnjs.cloudflare.com/ajax/libs/materialize/1.0.0/js/materialize.min.js https://files.stripe.com/v1/files https://analytics.tiktok.com https://*.forter.com https://d3in1te4fdays6.cloudfront.net https://d1wix2gc2cgqis.cloudfront.net wss://cdn0.forter.com https://cdn.cookielaw.org/consent/ https://cdn.cookielaw.org/ https://cdn.cookielaw.org/scripttemplates/ https://www.google-analytics.com https://www.google-analytics.com/j/collect app.pendo.io api.feedback.us.pendo.io *.salesforceliveagent.com https://stats.g.doubleclick.net https://tags.srv.stackadapt.com; frame-src 'self' *.myguestaccount.com https://app.getbee.io/ *; frame-ancestors 'self' app.pendo.io pxsweb.com *.pxsweb.com; img-src * blob: https://rs.fullstory.com data:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.cookiebot.com https://cookiebot.com *.px-cloud.net *.perimeterx.net *.px-cdn.net *.pxchk.net *.px-client.net https://*.myguestaccount.com https://*.api.sanity.io https://applepay.cdn-apple.com/jsapi/v1/apple-pay-sdk.js https://edge.fullstory.com https://rs.fullstory.com https://cdnjs.cloudflare.com/ajax/libs/materialize/1.0.0/js/materialize.min.js https://analytics.tiktok.com https://*.forter.com https://dkupaw9ae63a8.cloudfront.net https://js.stripe.com/v3 https://www.google-analytics.com https://cdn.cookielaw.org https://geolocation.onetrust.com/cookieconsentpub/v1/geo/location https://cdn.tailwindcss.com https://ssl.google-analytics.com https://www.google-analytics.com/analytics.js https://www.google-analytics.com/j/collect https://www.google.com/pagead/conversion_async.js https://use.typekit.net connect.facebook.net/ https://googleads.g.doubleclick.net/ app.pendo.io cdn.pendo.io pendo-static-5181968941056000.storage.googleapis.com pendo-io-static.storage.googleapis.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/api.js apis.google.com https://www.googletagmanager.com api.instagram.com https://app-rsrc.getbee.io/plugin/BeePlugin.js https://loader.getbee.io https://bat.bing.com/bat.js https://www.googleadservices.com/pagead/conversion.js https://connect.facebook.net/en_US/fbevents.js https://connect.facebook.net/ https://fonts.googleapis.com/ https://ssl.gstatic.com/ https://tagmanager.google.com/ https://core.spreedly.com/iframe/iframe-v1.min.js https://cdn.cookielaw.org/scripttemplates/otSDKStub.js https://cdn.cookielaw.org/scripttemplates/6.2.0/otBannerSdk.js https://www.googleadservices.com/pagead/conversion_async.js https://assets.sitescdn.net/ytag/ytag.min.js https://service.force.com/ *.salesforceliveagent.com https://tags.srv.stackadapt.com/events.js https://qvdt3feo.com/events.js; style-src 'unsafe-inline' *; worker-src 'self'; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=.crfXZ3h1KMnXXbQydtOaru6M8v8VpXfEN28TTU2v8I-1770865377-1.0.1.1-izKotgXsD5CgIN092Zcq184RTeV2KmzSVlF4l1iE2AkoovYgvbbAR5CfjPVymFsLNrcks7Ook7PwQYYR4Wi79YT_dPXVjuy5cFOTrkmpxp_oQ.sDdFvGNpqcpWH0Lyn0Nf1PNeTmfql1zmhleZX1GXezl_LBvr.rEtJ7XPdAOqTETfj1A6fq.lfji0y4LJsBnI1LXo.Zh0g0dR0DiMZZug; report-to cf-kptswgegmnwghfvf
Date
Other
Thu, 12 Feb 2026 03:02:57 GMT
Report-To
Other
{"endpoints":[{"url":"https:\/\/csp-reporting.cloudflare.com\/cdn-cgi\/script_monitor\/report?m=.crfXZ3h1KMnXXbQydtOaru6M8v8VpXfEN28TTU2v8I-1770865377-1.0.1.1-izKotgXsD5CgIN092Zcq184RTeV2KmzSVlF4l1iE2AkoovYgvbbAR5CfjPVymFsLNrcks7Ook7PwQYYR4Wi79YT_dPXVjuy5cFOTrkmpxp_oQ.sDdFvGNpqcpWH0Lyn0Nf1PNeTmfql1zmhleZX1GXezl_LBvr.rEtJ7XPdAOqTETfj1A6fq.lfji0y4LJsBnI1LXo.Zh0g0dR0DiMZZug"}],"group":"cf-kptswgegmnwghfvf","max_age":86400}

Recommendations

Enable compression (gzip/brotli) to improve performance

Consider removing X-Powered-By header to hide server technology