Cached · 6h ago
25 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Excellent
max-age=31536000 ; includeSubDomains ; preload
Content-Security-Policy
Good
default-src; script-src; style-src; +4 more
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
no-referrer
Permissions-Policy
Missing
Not configured
Recommendations
  • Strengthen CSP by removing 'unsafe-eval'
  • Consider adding Permissions-Policy to control browser features

Performance Headers

1 headers
Connection
Performance
close

Caching Headers

3 headers
Cache-Control
Caching
public, max-age=50336
Expires
Caching
Tue, 10 Feb 2026 06:56:38 GMT
Pragma
Caching
max-age=86400

Content Headers

3 headers
Content-Language
Content
en-us
Content-Length
Content
17559
Content-Type
Content
text/html; charset=UTF-8

Server Headers

1 headers
Server
Server
Google Frontend

CORS Headers

3 headers
Access-Control-Allow-Headers
Cors
Content-Type, Origin, accept, app_key, authorization
Access-Control-Allow-Methods
Cors
API, CRUNCHIFYGET, GET, POST, PUT, UPDATE, OPTIONS
Access-Control-Max-Age
Cors
86400

Cookies Headers

0 headers
No cookies headers found

Other Headers

9 headers
Date
Other
Mon, 09 Feb 2026 16:57:42 GMT
Surrogate-Control
Other
max-age=86400
Surrogate-Key
Other
8-eca7b481a4-jtkcdv 8356325 8-eca7b481a4-jtkcdv 6-a99c20-d0gq9h 11-fe61b8-c58dp1 6-e61bb4-8cgfrm 7-e634b4-5m8s5t 11-caa4bbe4f4-hjnst0 11-dab000-t42fq9 11-358820-7t2fm5 11-96cbc584d6-290t8m 11-68715c-j6ngst 11-673a5c-k8qjnw 11-3d4960-dpnswm 6-88ddbaf6dc-6ggvpn 6-d885a6bb9f-b01nrk
Z-Branch
Other
live
Z-Cdn
Other
AKAMAI
Z-Content-Version
Other
155:9-92d08cf8f5-5lz98j
Z-Content-Zuid
Other
7-e634b4-5m8s5t
Z-Engine
Other
WebEngine
Z-Zuid
Other
8-eca7b481a4-jtkcdv

Recommendations

Enable compression (gzip/brotli) to improve performance