Open
Cached
·
just now
21
Headers
Detected Technologies from Headers
Google AdSense
Ably
Google Tag Manager
G2
Google reCAPTCHA
Google Cloud Run
Amplitude
Reddit
Webflow
HubSpot Forms
Active incidents
Zapier
Cello
Google DoubleClick
Google Analytics
Microsoft Advertising
Cloudflare CDN
Google Cloud Storage
Google Static File Front End
Google API JS Client
TikTok Analytics
Google Fonts
Twitter
Algolia
Hotjar
LinkedIn
ZoomInfo
Cloudflare Turnstile
Stripe
HubSpot Analytics
Active incidents
Google Search
Apple ID
Facebook
OneTrust
Rewardful
MNTN
Google Optimize
PostHog
HubSpot
Active incidents
Intercom
YouTube
Sentry
Active incidents
Google Cloud
Next.js
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=15552000; includeSubDomains
X-Frame-Options
Good
sameorigin
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
Transfer-Encoding
chunked
Vary
Accept-Encoding
connection: close transfer-encoding: chunked vary: Accept-Encoding
Caching Headers
Age
59740
Cache-Control
no-cache, no-store, must-revalidate
age: 59740 cache-control: no-cache, no-store, must-revalidate
Content Headers
Content-Type
text/html; charset=utf-8
content-type: text/html; charset=utf-8
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Cf-Placement
local-IAD
Date
Thu, 16 Apr 2026 15:31:27 GMT
Via
1.1 google
X-Robots-Tag
noindex
cf-cache-status: HIT cf-placement: local-IAD cf-ray: 9ed43cb2aacd59ec-IAD date: Thu, 16 Apr 2026 15:31:27 GMT via: 1.1 google x-nextjs-cache: HIT x-robots-tag: noindex
Recommendations
Enable compression (gzip/brotli) to improve performance