Open
Cached
·
just now
22
Headers
Detected Technologies from Headers
PayPal
Adobe Target
YouTube
Google Tag Manager
Bing
Google Cloud Run
Braintree
Reddit
Google DoubleClick
Google Pay
Google Analytics
Adobe Audience Manager
New Relic
Typeform
Google Static File Front End
Varnish
Google API JS Client
Google Fonts
Twitter
Klaviyo
Adobe Experience Cloud
unpkg
Google Search
Nginx
Adobe Dynamic Tag Management
Facebook
Snapchat
Adobe Fonts (Typekit)
PHP
Pinterest
TikTok
Vimeo
Microsoft Clarity
Font Awesome
Sentry
Google Cloud
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Present
SAMEORIGIN, SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Accept-Ranges
bytes
Connection
close
Transfer-Encoding
chunked
Vary
Accept-Encoding
accept-ranges: bytes connection: close transfer-encoding: chunked vary: Accept-Encoding
Caching Headers
Cache-Control
no-store, no-cache, must-revalidate, max-age=0
Expires
-1
Pragma
no-cache
cache-control: no-store, no-cache, must-revalidate, max-age=0 expires: -1 pragma: no-cache
Content Headers
Content-Type
text/html; charset=UTF-8
content-type: text/html; charset=UTF-8
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Date
Sat, 30 May 2026 22:03:32 GMT
X-Cache
MISS
X-Cache-Nxaccel
BYPASS
X-Cache-Via
varnish
X-Host
snapfireworks.com
X-Ua-Compatible
IE=edge
X-Varnish-Age
0
date: Sat, 30 May 2026 22:03:32 GMT x-cache: MISS x-cache-nxaccel: BYPASS x-cache-via: varnish x-host: snapfireworks.com x-ua-compatible: IE=edge x-varnish: 722822134 x-varnish-age: 0
Recommendations
Enable compression (gzip/brotli) to improve performance