Open
Cached
·
just now
13
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains
Content-Security-Policy
Basic
default-src; script-src; style-src; +8 more
default-src 'self' data: 'unsafe-inline' 'unsafe-hashes' 'unsafe-eval' embed.figma.com figma.com https://*.superopsmsp.com https://*.superops.ai blob:; script-src 'self' data: 'unsafe-inline' 'unsafe-hashes' 'unsafe-eval' https://*.getbeamer.com https://*.google.com https://*.superops.com https://*.superops.ai https://*.mysuperops.com https://www.gstatic.com assets.superopsmsp.com https://*.chameleon.io https://*.commandbar.com https://embed.figma.com https://*.figma.com https://unpkg.com cdn.mxpnl.com fast.appcues.com js.chargebee.com *.jsdelivr.net js.stripe.com widget.intercom.io canny.io js.intercomcdn.com blob:; style-src 'self' data: 'unsafe-inline' 'unsafe-hashes' https://*.getbeamer.com https://*.commandbar.com https://embed.figma.com https://api.fontshare.com https://*.figma.com https://*.superops.ai https://*.superops.com js.chargebee.com *.jsdelivr.net fonts.googleapis.com fast.appcues.com; img-src * 'self' data: https://*.superops.ai https://*.chameleon.io https://embed.figma.com https://*.figma.com https://*.superopsmsp.com https://*.commandbar.com https://*.googleusercontent.com https://galaxy-attachments-prod.s3.us-east-2.amazonaws.com https://eu-galaxy-attachments-prod.s3.eu-central-1.amazonaws.com https://downloads.intercomcdn.com https://js.intercomcdn.com https://static.intercomassets.com https://i.ytimg.com galaxy-attachments-prestage.s3.us-east-2.amazonaws.com galaxy-attachments-stage.s3.us-east-2.amazonaws.com galaxy-attachments-dev.s3.us-east-2.amazonaws.com galaxy-attachments-prod.s3.us-east-2.amazonaws.com https://www.gstatic.com blob:; font-src 'self' data: https://*.superops.ai https://*.chameleon.io https://*.figma.com https://js.intercomcdn.com https://fonts.intercomcdn.com https://fonts.gstatic.com https://www.gstatic.com https://cdn.fontshare.com js.stripe.com; connect-src 'self' ws: wss: api.appcues.net https://*.superops.ai https://*.superops.com https://*.mysuperops.com https://api.ipstack.com https://*.getbeamer.com https://cdn.fontshare.com https://*.chameleon.io https://*.figma.com https://unpkg.com https://*.superopsmsp.com https://*.commandbar.com https://public-api.freshstatus.io https://session-replay.browser-intake-datadoghq.com https://rum.browser-intake-datadoghq.com https://rum.browser-intake-us5-datadoghq.com/ https://api-js.mixpanel.com https://uploads.intercomcdn.com/ fast.appcues.com galaxy-attachments-prestage.s3.us-east-2.amazonaws.com events.launchdarkly.com clientstream.launchdarkly.com api-iam.intercom.io app.launchdarkly.com appcues.com https://*.bettermode.com https://ingress.us1.rum-ingress-coralogix.com https://ingress.eu2.rum-ingress-coralogix.com https://*.intercom-messenger.com wss://*.intercom-messenger.com; media-src 'self' https://*.superops.ai https://*.superops.com https://embed.figma.com https://*.figma.com https://*.commandbar.com https://js.intercomcdn.com; object-src 'self'; prefetch-src 'self'; frame-ancestors 'self' https://*.superops.ai http://wails.localhost wails://wails https://wails.localhost; frame-src 'self' https://*.getbeamer.com https://play.google.com https://*.superops.ai https://*.superops.com https://*.mysuperops.com https://*.chameleon.io https://www.gstatic.com https://www.google.com https://embed.figma.com https://*.figma.com https://*.commandbar.com https://widget.dromo.io https://superops.chargebee.com js.chargebee.com https://intercom-sheets.com https://www.youtube.com https://www.youtube-nocookie.com fast.appcues.com js.stripe.com
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Present
geolocation=(),microphone=(),camera=()
Recommendations
- • Consider adding 'preload' to HSTS for maximum security
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
Performance Headers
3 headers
Accept-Ranges
Performance
bytes
Connection
Performance
close
Vary
Performance
Accept-Encoding
Caching Headers
2 headers
Etag
Caching
"6964850c-269f"
Last-Modified
Caching
Mon, 12 Jan 2026 05:22:20 GMT
Content Headers
2 headers
Content-Length
Content
9887
Content-Type
Content
text/html
Server Headers
1 headers
Server
Server
nginx
CORS Headers
0 headers
No CORS headers found
Cookies Headers
0 headers
No cookies headers found
Other Headers
2 headers
Date
Other
Mon, 12 Jan 2026 06:53:43 GMT
Feature-Policy
Other
camera 'none'; microphone 'none'; geolocation 'none'
Recommendations
Enable compression (gzip/brotli) to improve performance
Add Cache-Control header to optimize caching