Open
Cached
·
2h ago
17
Headers
Detected Technologies from Headers
AWS CloudFront
Advertising.com
Akamai
Active incidents
Apache Traffic Server
AppNexus (Xandr)
AWS
Active incidents
Bing
Cloudflare CDNJS
Criteo
Envoy
Facebook
Google Analytics
Google API JS Client
Google DoubleClick
Google Static File Front End
Google Tag Manager
jsDelivr
Outbrain
PubMatic
Teads
TripleLift
unpkg
Yahoo
Yieldmo
YouTube
Express
Google Cloud
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
no-referrer-when-downgrade
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
Vary
Accept-Encoding
connection: close vary: Accept-Encoding
Caching Headers
Age
0
Cache-Control
no-cache
Etag
W/"4c24b-+CQaXd1+Jydjo5bB4YE3T2GLRZc"
age: 0 cache-control: no-cache etag: W/"4c24b-+CQaXd1+Jydjo5bB4YE3T2GLRZc"
Content Headers
Content-Length
311883
Content-Type
text/html; charset=utf-8
content-length: 311883 content-type: text/html; charset=utf-8
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
date: Sun, 04 Oct 2026 21:25:11 GMT x-envoy-upstream-service-time: 67
Recommendations
Enable compression (gzip/brotli) to improve performance
Consider removing X-Powered-By header to hide server technology