Open
Cached
·
just now
26
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains
Content-Security-Policy
Basic
script-src; default-src; style-src; +10 more
script-src 'nonce-c9ddc66f-eab1-4e3d-bc3a-58de5bd1a86d' 'self' *.garmin.com *.trustarc.com *.truste.com https://ajax.googleapis.com https://static.garmincdn.com https://www.google.com https://cdn.appdynamics.com https://www.gstatic.com https://prefmgr-cookie.truste-svc.net https://connect.facebook.net https://www.googleadservices.com https://*.doubleclick.net https://static.criteo.net https://*.criteo.com https://bat.bing.com https://*.adform.net https://intljs.rmtag.com https://www.googletagmanager.com https://*.realytics.io https://klear.com https://px.adentifi.com https://cdn-eu.realytics.net https://secure.adnxs.com https://p.teads.tv https://js.adsrvr.org https://tag.rmp.rakuten.com https://s.pinimg.com https://sc-static.net https://*.snapchat.com https://ct.pinterest.com https://snap.licdn.com https://px.ads.linkedin.com https://*.google-analytics.com https://static.cloudflareinsights.com https://static.hotjar.com https://script.hotjar.com https://optimize.google.com https://members.cj.com static-pages.fe.garmin.com http://tags.tiqcdn.com https://*.tealiumiq.com https://deploytealium.com 'unsafe-eval' 'unsafe-inline' https://members.cj.com/member/publisherBookmarklet.js;default-src 'self' *.garmin.com https://static.garmincdn.com;style-src 'self' 'unsafe-inline' *.garmin.com https://static.garmincdn.com https://fonts.googleapis.com https://static.hotjar.com https://script.hotjar.com https://members.cj.com/member/javascript/publisher/bookmarklet/publisher-bookmarklet.css https://members.cj.com/member/styles/fonts/cj-icon-web-font/cj-icon-font.css;connect-src 'self' *.garmin.com *.sentry.io https://static.garmincdn.com https://*.cloudinary.com https://www.gstatic.com https://*.doubleclick.net https://*.criteo.com https://*.linksynergy.com https://*.bing.com https://*.pinterest.com https://*.snapchat.com https://px.ads.linkedin.com https://*.google-analytics.com https://analytics.google.com https://*.analytics.google.com https://stats.g.doubleclick.net https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com *.googlesyndication.com https://*.googlesyndication.com https://*.google.com https://akamai.tiqcdn.com https://*.akamaihd.net *.trustarc.com;font-src 'self' data: *.garmin.com *.trustarc.com *.truste.com https://static.garmincdn.com https://fonts.googleapis.com https://fonts.gstatic.com https://script.hotjar.com https://members.cj.com/member/styles/fonts/;img-src 'self' data: *.garmin.com *.trustarc.com *.truste.com https://static.garmincdn.com https://www.google.com https://www.google.co.uk https://prefmgr-cookie.truste-svc.net https://res.cloudinary.com https://res.garmin.com https://*.criteo.com https://*.doubleclick.net https://www.googleadservices.com https://px.adentifi.com https://rtb.adentifi.com https://*.teads.tv https://www.googletagmanager.com https://bat.bing.com https://secure.adnxs.com https://www.facebook.com https://*.yahoo.com https://sync.outbrain.com https://*.google-analytics.com https://stats.g.doubleclick.net https://static.hotjar.com https://script.hotjar.com *.akamaihd.net https://*.tealiumiq.com https://deploytealium.com https://pixel.mediaiqdigital.com https://members.cj.com/member/javascript/ui-kit/images/close_icon.png;frame-src *.garmin.com *.trustarc.com *.truste.com https://static.garmincdn.com https://www.google.com https://prefmgr-cookie.truste-svc.net https://*.googletagmanager.com https://*.doubleclick.net https://*.criteo.com https://www.youtube-nocookie.com https://insight.adsrvr.org https://*.snapchat.com https://ct.pinterest.com https://members.cj.com;object-src 'none';upgrade-insecure-requests;base-uri 'self';form-action 'self';frame-ancestors 'self';script-src-attr 'none'
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
no-referrer-when-downgrade
Permissions-Policy
Missing
Not configured
Recommendations
- • Consider adding 'preload' to HSTS for maximum security
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Consider adding Permissions-Policy to control browser features
Performance Headers
3 headers
Connection
Performance
close
Transfer-Encoding
Performance
chunked
Vary
Performance
Accept-Encoding
Caching Headers
2 headers
Age
Caching
6398
Cache-Control
Caching
public, max-age=7200
Content Headers
1 headers
Content-Type
Content
text/html; charset=utf-8
Server Headers
1 headers
Server
Server
cloudflare
CORS Headers
0 headers
No CORS headers found
Cookies Headers
1 headers
Set-Cookie
Cookies
_cfuvid=Vht3unhzsRCS5CftwUq8RAKwBGaMEyqYYn2fhAhYR2U-1768347391706-0.0.1.1-604800000; path=/; domain=.www.garmin.com; HttpOnly; Secure; SameSite=None
Other Headers
12 headers
Cf-Cache-Status
Other
HIT
Cf-Ray
Other
9bd8b75daf160a95-IAD
Date
Other
Tue, 13 Jan 2026 23:36:31 GMT
Nel
Other
{"success_fraction":0.01,"report_to":"cf-nel","max_age":604800}
Origin-Agent-Cluster
Other
?1
Report-To
Other
{"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=ZYn0xeCsLcMHGeHvODXZE1I7fnkjBHIGsNLKgvEtbvVJZrWELwwTbE9qgUsxfkesBbsVoxrqV8JJLwuCn87Z59F%2FZJ9NAyaqbQ8KxilyHHJNSYJ5QCOW%2BBoNrprGRgX3"}],"group":"cf-nel","max_age":604800}
X-Application-Context
Other
OLA
X-Application-Id
Other
WWW_CATEGORY_PAGES
X-Application-Platform
Other
GPC
X-Dns-Prefetch-Control
Other
off
X-Locale
Other
en-US
X-Permitted-Cross-Domain-Policies
Other
none
Recommendations
Enable compression (gzip/brotli) to improve performance