Open
Cached
·
just now
22
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Excellent
max-age=31536000; includeSubDomains;preload
Content-Security-Policy
Good
default-src; script-src; style-src; +10 more
default-src 'self' https:; script-src 'self' 'nonce-PgzR4vVfu3io3LQ/Hr3IwA==' 'strict-dynamic' *.calibermind.com *.hs-scripts.com js.hs-analytics.net blob: *.hs-banner.com *.cookielaw.org *.hubspot.com js.hsadspixel.net pi.pardot.com tag.demandbase.com scripts.saltbox.tech player.vimeo.com go.rapidscale.net js.zi-scripts.com *.ads-twitter.com *.facebook.net *.licdn.com *.doubleclick.net *.google-analytics.com *.googletagmanager.com *.googleapis.com *.jsdelivr.net *.cloudflare.com *.youtube.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com edge.marker.io cdn.polyfill.io; style-src 'self' 'unsafe-inline' *.googleapis.com; font-src 'self' data: *.gstatic.com; img-src 'self' https: data:; frame-src 'self' *.commoninja.com *.genially.com *.googletagmanager.com *.vimeo.com *.company-target.com pixel.sitescout.com *.facebook.com *.adsrvr.org *.liadm.com *.doubleclick.net *.hsforms.com *.hsforms.net *.youtube.com *.google.com *.youtube-nocookie.com; form-action 'self' *.facebook.com *.hsforms.net *.hsforms.com; base-uri 'self'; connect-src 'self' *.googletagmanager.com *.calibermind.com *.commoninja.com google.com *.google.com *.hsforms.com *.liadm.com *.adsrvr.org *.clickagy.com *.linkedin.com api.hubapi.com *.hubspot.com ws.zoominfo.com *.onetrust.com *.demandbase.com *.company-target.com cdn.cookielaw.org js.zi-scripts.com *.doubleclick.net *.google-analytics.com *.googleapis.com *.licdn.com *.hsforms.net https://hubspot-forms-static-embed.s3.amazonaws.com https://static.hsappstatic.net; frame-ancestors 'self'; object-src 'none'; media-src 'self' https:; manifest-src 'self' https:;
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
no-referrer-when-downgrade
Permissions-Policy
Missing
Not configured
Recommendations
- • Strengthen CSP by removing 'unsafe-eval'
- • Consider adding Permissions-Policy to control browser features
Performance Headers
3 headers
Connection
Performance
close
Transfer-Encoding
Performance
chunked
Vary
Performance
Accept-Encoding,Cookie
Caching Headers
1 headers
Cache-Control
Caching
no-cache
Content Headers
1 headers
Content-Type
Content
text/html; charset=UTF-8
Server Headers
1 headers
Server
Server
nginx
CORS Headers
0 headers
No CORS headers found
Cookies Headers
1 headers
Set-Cookie
Cookies
incap_ses_1291_2196371=cOI+Y3nhIBeOnkQOIo7qEatRcGkAAAAAxDJ/PG+Nf1KZKJnijb/noQ==; path=/; Domain=.rapidscale.net; Secure; SameSite=None
Other Headers
9 headers
Date
Other
Wed, 21 Jan 2026 04:10:20 GMT
Feature-Policy
Other
sync-xhr 'self'
Host-Header
Other
6b7412fb82ca5edfd0917e3957f05d89
X-Cdn
Other
Imperva
X-Httpd
Other
1
X-Iinfo
Other
14-99572670-99572675 NNNY CT(17 46 0) RT(1768968619991 24) q(0 1 1 1) r(1 1) U24
X-Permitted-Cross-Domain-Policies
Other
none
X-Proxy-Cache
Other
MISS
X-Proxy-Cache-Info
Other
0 NC:000000 UP:
Recommendations
Enable compression (gzip/brotli) to improve performance