Open
Cached
·
just now
14
Headers
Detected Technologies from Headers
PayPal
Adobe Fonts (Typekit)
Apple ID
Microsoft Advertising
Facebook
Google Analytics
Google API JS Client
Google DoubleClick
Google Fonts
Google Static File Front End
Google Sign-In
Google Tag Manager
LinkedIn
Nginx
Outbrain
Quora
Reddit
Sentry
Stripe
TikTok Analytics
Twitter
WordPress
WordPress.com
YouTube
Zendesk
Google Cloud
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000; preload
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
Vary
Accept-Encoding
connection: close vary: Accept-Encoding
Caching Headers
Cache-Control
no-store
cache-control: no-store
Content Headers
Content-Length
125997
Content-Type
text/html; charset=utf-8
content-length: 125997 content-type: text/html; charset=utf-8
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Alt-Svc
h3=":443"; ma=86400
Date
Wed, 08 Apr 2026 21:14:16 GMT
Server-Timing
a8c-cdn, dc;desc=dca, cache;desc=BYPASS;dur=1218.0
X-Ac
2.dca _dca BYPASS
alt-svc: h3=":443"; ma=86400 date: Wed, 08 Apr 2026 21:14:16 GMT server-timing: a8c-cdn, dc;desc=dca, cache;desc=BYPASS;dur=1218.0 x-ac: 2.dca _dca BYPASS
Recommendations
Enable compression (gzip/brotli) to improve performance