Open
Cached
·
3m ago
21
Headers
Detected Technologies from Headers
AWS CloudFront
Algolia
Arcade
ClearBit
Firebase
Google Analytics
Google API JS Client
Google Cloud Functions
Google Cloud Storage
Google DoubleClick
Google Fonts
Google Hosted Libraries
Google Static File Front End
Google Tag Manager
HubSpot
HubSpot Analytics
HubSpot Forms
Intercom
jsDelivr
LinkedIn
Liveblocks
Mux
Pexels
PostHog
Sentry
Stripe
Vercel
Google Cloud
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=63072000
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Accept-Ranges
bytes
Connection
close
accept-ranges: bytes connection: close
Caching Headers
Age
72312
Cache-Control
public, max-age=0, must-revalidate
Etag
"6310108475b2cab3c86910ebd3bde7c5"
Last-Modified
Tue, 06 Oct 2026 02:00:03 GMT
age: 72312 cache-control: public, max-age=0, must-revalidate etag: "6310108475b2cab3c86910ebd3bde7c5" last-modified: Tue, 06 Oct 2026 02:00:03 GMT
Content Headers
Content-Disposition
inline; filename="auth"
Content-Length
5035
Content-Type
text/html; charset=utf-8
content-disposition: inline; filename="auth" content-length: 5035 content-type: text/html; charset=utf-8
CORS Headers
Access-Control-Allow-Origin
*
access-control-allow-origin: *
Cookies Headers
Other Headers
Date
Tue, 06 Oct 2026 22:05:16 GMT
X-Dns-Prefetch-Control
on
X-Matched-Path
/auth
date: Tue, 06 Oct 2026 22:05:16 GMT x-dns-prefetch-control: on x-matched-path: /auth x-vercel-cache: HIT x-vercel-id: iad1::lltww-1791324316125-dd664e9d1c84
Recommendations
Enable compression (gzip/brotli) to improve performance