Cached · just now
24 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31536000
Content-Security-Policy
Weak
upgrade-insecure-requests
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Good
no-referrer-when-downgrade
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Significantly strengthen CSP directives
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Consider adding Permissions-Policy to control browser features

Performance Headers

2 headers
Connection
Performance
close
Transfer-Encoding
Performance
chunked

Caching Headers

2 headers
Cache-Control
Caching
s-maxage=36000, max-age=5
Last-Modified
Caching
Thu, 25 Dec 2025 10:02:12 GMT

Content Headers

1 headers
Content-Type
Content
text/html; charset=UTF-8

Server Headers

1 headers
Server
Server
cloudflare

CORS Headers

0 headers
No CORS headers found

Cookies Headers

1 headers
Set-Cookie
Cookies
_cfuvid=SzbcqGoqC2Te3NAiJFQZjE6UNr_QIDAo9ZdHsdGl.Nc-1767073050231-0.0.1.1-604800000; path=/; domain=.www.tumelo.com; HttpOnly; Secure; SameSite=None

Other Headers

14 headers
Alt-Svc
Other
h3=":443"; ma=86400
Cf-Ray
Other
9b5f2f83abca86a3-MAD
Content-Security-Policy-Report-Only
Other
Date
Other
Tue, 30 Dec 2025 05:37:30 GMT
Edge-Cache-Tag
Other
CT-60616456428,P-25524212,CW-60356089587,CW-60356089800,CW-60356686023,CW-60357415645,CW-60357415649,CW-60486770362,CW-60564010488,CW-60730411718,E-60356089813,E-60356089837,E-60356090050,E-60356686048,E-60356686051,E-60356686271,E-60356686273,E-60357099461,E-60357099469,E-60357415869,E-60357415877,PGS-ALL,SW-0,GC-60585102012,GC-60749815288,GC-60753265641,TS-60356090076
Link
Other
<https://fonts.googleapis.com>; rel=preconnect,<https://fonts.gstatic.com>; rel=preconnect,<https://fonts.googleapis.com/css2?family=Montserrat:ital,wght@0,100;0,200;0,300;0,400;0,500;0,600;0,700;0,800;0,900;1,100;1,200;1,300;1,400;1,500;1,600;1,700;1,800;1,900&display=swap>; rel=preload; as=style,<https://25524212.fs1.hubspotusercontent-eu1.net/hubfs/25524212/hub_generated/template_assets/1/60356686048/1765543630366/template_main.min.css>; rel=preload; as=style,<https://25524212.fs1.hubspotusercontent-eu1.net/hubfs/25524212/hub_generated/module_assets/1/60357415649/1744338508701/module_Website_Header.min.css>; rel=preload; as=style,<https://25524212.fs1.hubspotusercontent-eu1.net/hubfs/25524212/hub_generated/module_assets/1/60356686023/1744338504786/module_Custom_Image.min.css>; rel=preload; as=style
X-Hs-Cache-Config
Other
BrowserCache-5s-EdgeCache-180s
X-Hs-Cache-Control
Other
s-maxage=36000, max-age=0
X-Hs-Cf-Cache-Status
Other
HIT
X-Hs-Cfworker-Meta
Other
{"contentType":"SITE_PAGE","resolver":"PreRenderedContentResolver"}
X-Hs-Content-Id
Other
60616456428
X-Hs-Hub-Id
Other
25524212
X-Hs-Portal-Id
Other
25524212
X-Hs-Prerendered
Other
Thu, 25 Dec 2025 10:02:12 GMT

Recommendations

Enable compression (gzip/brotli) to improve performance