Open
Cached
·
just now
20
Headers
Detected Technologies from Headers
AWS CloudFront
Shields.io
Google Tag Manager
Bugsnag
Bing
G2
HackerOne
Google Cloud Run
RudderStack
AppNexus (Xandr)
Sanity
Fullstory
Mutiny
Reddit
Webflow
Google DoubleClick
Arcade
Google Analytics
Microsoft Advertising
Pusher
6sense
Google Static File Front End
Next.js
Calendly
Google API JS Client
Twitter
Algolia
Hotjar
Hex
LinkedIn
Google Search
Ketch
Qualified
Kapa AI
GitHub
Vercel
jQuery
IP-API
PostHog
Vector
Quora
YouTube
Microsoft Clarity
Font Awesome
jsDelivr
Google Cloud
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=63072000
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
no-referrer-when-downgrade
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
Vary
rsc, next-router-state-tree, next-router-prefetch, next-router-segment-prefetch
connection: close vary: rsc, next-router-state-tree, next-router-prefetch, next-router-segment-prefetch
Caching Headers
Age
32519
Cache-Control
public, max-age=0, must-revalidate
Etag
"u6m3q067qdjqy9"
age: 32519 cache-control: public, max-age=0, must-revalidate etag: "u6m3q067qdjqy9"
Content Headers
Content-Length
921449
Content-Type
text/html; charset=utf-8
content-length: 921449 content-type: text/html; charset=utf-8
Server Headers
server: Vercel x-powered-by: Next.js
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Date
Mon, 06 Apr 2026 20:45:45 GMT
X-Matched-Path
/[[...slug]]
date: Mon, 06 Apr 2026 20:45:45 GMT x-matched-path: /[[...slug]] x-nextjs-prerender: 1 x-nextjs-stale-time: 300 x-vercel-cache: HIT x-vercel-id: iad1::iad1::w62g8-1775540865009-77c4e51e9e93
Recommendations
Enable compression (gzip/brotli) to improve performance
Consider removing X-Powered-By header to hide server technology