Open
Cached
·
just now
24
Headers
Detected Technologies from Headers
PayPal
Auth0
Google Tag Manager
Fullstory
WordPress
Liveblocks
HubSpot Forms
Cookiebot
HubSpot Feedback & Surveys
Google DoubleClick
Google Analytics
ClearBit
Dropbox
Mixpanel
Segment
Cloudflare CDN
Datadog
Google Cloud Storage
Google Static File Front End
Google Fonts
Wistia
Svix
Transcend
Loom
LinkedIn
Stripe
HubSpot Analytics
Google Search
Facebook
OneTrust
Adobe Fonts (Typekit)
Split.io
Vimeo
Statsig
HubSpot
Intercom
YouTube
HubSpot Live Chat
Sentry
Google Cloud
HTTP Security Headers
Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Present
no-referrer,strict-origin-when-cross-origin
Permissions-Policy
Missing
Not configured
Recommendations
- • Consider adding 'preload' to HSTS for maximum security
- • Strengthen CSP by removing 'unsafe-eval'
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
Transfer-Encoding
chunked
Vary
Accept-Encoding
connection: close transfer-encoding: chunked vary: Accept-Encoding
Caching Headers
Age
2199
Cache-Control
private, no-cache, no-store, max-age=0, must-revalidate
age: 2199 cache-control: private, no-cache, no-store, max-age=0, must-revalidate
Content Headers
Content-Type
text/html; charset=utf-8
content-type: text/html; charset=utf-8
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Date
Sat, 21 Feb 2026 20:40:06 GMT
Document-Policy
js-profiling
Origin-Agent-Cluster
?1
Via
1.1 google
X-Dns-Prefetch-Control
off
X-Download-Options
noopen
X-Permitted-Cross-Domain-Policies
none
cf-cache-status: HIT cf-ray: 9d190e925fa48792-IAD date: Sat, 21 Feb 2026 20:40:06 GMT document-policy: js-profiling origin-agent-cluster: ?1 via: 1.1 google x-dns-prefetch-control: off x-download-options: noopen x-permitted-cross-domain-policies: none
Recommendations
Enable compression (gzip/brotli) to improve performance