Open
Cached
·
just now
22
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Consider adding 'preload' to HSTS for maximum security
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
1 headers
Connection
Performance
close
Caching Headers
3 headers
Cache-Control
Caching
no-cache, no-store, max-age=0, must-revalidate
Expires
Caching
0
Pragma
Caching
no-cache
Content Headers
1 headers
Content-Length
Content
0
Server Headers
1 headers
Server
Server
cloudflare
CORS Headers
0 headers
No CORS headers found
Cookies Headers
1 headers
Set-Cookie
Cookies
__cf_bm=rLo22GQvswmEC6ZxD.eFpGjeY5sOCYA4aStWs0j6iaM-1767335903-1.0.1.1-Lf4DoM3gc04vFJePNPph_ML23wnQ2nf9NH_77eNutl8cmY365dfeQkacdQucp8noK8lz1HMVLf01N.m4RQg7G1vRSP.ctStuJQNluppR.w0; path=/; expires=Fri, 02-Jan-26 07:08:23 GMT; domain=.freshworks.com; HttpOnly; Secure; SameSite=None
Other Headers
11 headers
Cf-Cache-Status
Other
DYNAMIC
Cf-Ray
Other
9b7840d32a8d3b23-IAD
Date
Other
Fri, 02 Jan 2026 06:38:23 GMT
Location
Other
https://ecoitny.freshdesk.com/freshid/authorize_callback?hd=https://ecoitny.freshdesk.com&error=login_required&error_description=user_login_is_required
Nel
Other
{ "report_to": "nel-endpoint-freshworks360", "max_age": 2592000, "include_subdomains": true}
Report-To
Other
{ "group": "nel-endpoint-freshworks360", "max_age": 2592000, "include_subdomains": true, "endpoints": [{"url": "https://edge-admin.us-east-1.freshedge.net/nelreports/freshworks360"}]}
X-Envoy-Upstream-Service-Time
Other
10
X-Request-Id
Other
a178df10-d865-4c9b-ac86-7797e71c3ddb
X-Server-Processing-Time-Ms
Other
23
X-Trace-Id
Other
00-242081e2d2bd2b5a248bb9ec98ddf87a-2132be7dcee7cafd-00
X-Xsrf-Token
Other
26707d4b-f90c-4b8a-820b-601c3e1680e3.xSpAuTHbopsMCKVVV7La1WknOmphgv50B8JmVafMDMM=
Recommendations
Enable compression (gzip/brotli) to improve performance