Open
Cached
·
26m ago
13
Headers
Detected Technologies from Headers
Microsoft Entra ID
AWS CloudFront
YouTube
Google AdSense
Google Maps
Google Tag Manager
G2
HubSpot Forms
Microsoft Azure
Google DoubleClick
Google Analytics
Google Cloud Storage
Google Static File Front End
Calendly
Google API JS Client
Google Fonts
Clickagy
Wistia
LinkedIn
ZoomInfo
ShareThis
HubSpot Analytics
Drift
Active incidents
ASP.NET
Google Search
Qualified
Facebook
Amazon S3
Lucky Orange
Storyblok
Cloudflare CDNJS
TrustArc
Google Optimize
Convert
JW Player
HubSpot
Font Awesome
Sentry
Google Cloud
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
connection: close
Caching Headers
Cache-Control
max-age=1
cache-control: max-age=1
Content Headers
Content-Length
167562
Content-Type
text/html; charset=utf-8
content-length: 167562 content-type: text/html; charset=utf-8
CORS Headers
Access-Control-Allow-Headers
Accept, Origin, Content-Type
Access-Control-Allow-Methods
GET, POST, PUT, DELETE, OPTIONS
Access-Control-Allow-Origin
*
access-control-allow-headers: Accept, Origin, Content-Type access-control-allow-methods: GET, POST, PUT, DELETE, OPTIONS access-control-allow-origin: *
Cookies Headers
Other Headers
Date
Wed, 13 May 2026 09:59:52 GMT
date: Wed, 13 May 2026 09:59:52 GMT
Recommendations
Enable compression (gzip/brotli) to improve performance
Consider removing X-Powered-By header to hide server technology