Open
Cached
·
just now
12
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Good
max-age=63072000; includeSubDomains
Content-Security-Policy
Basic
script-src; img-src; style-src; +5 more
script-src 'self' 'unsafe-inline' 'unsafe-eval' mw-uk2-uat.thehut.net mw.thghosting.com *.midphase.com *.uk2group.com request.eprotect.vantivprelive.com request.eprotect.vantivcnp.com http://static.hotjar.com https://static.hotjar.com https://script.hotjar.com *.dwin1.com *.hsforms.com *.hsforms.net *.puzzel.com *.google.com *.google.co.uk *.googleapis.com *.gdmdigital.com *.bing.com *.jquery.com platform.linkedin.com www.linkedin.com platform.twitter.com *.pingdom.net *.websitealive.com m.addthisedge.com ssl.google-analytics.com *.addthis.com *.trustpilot.com *.cloudfront.net *.visualwebsiteoptimizer.com *.adroll.com *.facebook.net www.googleadservices.com *.qualtrics.com www.google.com apis.google.com www.googletagmanager.com www.google-analytics.com cdn.syndication.twimg.com syndication.twitter.com platform.twitter.com fp.gdmdigital.com connect.facebook.net app.yieldify.com yieldify.com www.gstatic.com *.cloudfront.net tracking.websitealive.com secure.adnxs.com www.youtube.com s.ytimg.com *.hcaptcha.com; img-src 'self' *.thgingenuity.com img.zohostatic.eu *.midphase.com *.uk2group.com *.puzzel.com *.bing.com www.linkedin.com *.gravatar.com ssl.google-analytics.com *.pingdom.net *.websitealive.com *.adroll.com *.licdn.com *.twimg.com *.bidswitch.net *.rlcdn.com *.licdn.com www.privacytrust.com *.twitter.com *.openx.net *.doubleclick.net *.cloudfront.net *.adnxs.com go.flx1.com pbs.twimg.com platform.twitter.com *.facebook.com csi.gstatic.com syndication.twitter.com s.c.lnkd.licdn.com *.etrust.org *.gstatic.com 55b558c7-resources.bk-partnersasia.com *.visualwebsiteoptimizer.com www.google-analytics.com www.facebook.com www.google.com www.google.co.uk stats.g.doubleclick.net data: https://script.hotjar.com http://script.hotjar.com; style-src 'self' 'unsafe-inline' *.midphase.com *.twitter.com *.puzzel.com *.google.com *.pingdom.net *.websitealive.com fonts.googleapis.com maxcdn.bootstrapcdn.com *.cloudfront.net; frame-src 'self' *.midphase.com cdn.forms-content.sg-form.com *.uk2group.com *.puzzel.com *.hsforms.com *.hsforms.net *.facebook.net *.facebook.com https://vars.hotjar.com *.twitter.com *.websitealive.com staticxx.facebook.com *.addthis.com *.trustpilot.com *.google.com www.youtube.com app.yieldify.com accounts.google.com apis.google.com www.facebook.com *.hcaptcha.com; connect-src 'self' *.hcaptcha.com *.google-analytics.com *.sentry.io mw-uk2-uat.thehut.net mw.thghosting.com *.midphase.com m.addthis.com *.puzzel.com *.trustpilot.com *.pingdom.net *.twitter.com ws://127.0.0.1:35729 http://*.hotjar.com:* https://*.hotjar.com:* https://vc.hotjar.io:* https://surveystats.hotjar.io wss://*.hotjar.com *.visualwebsiteoptimizer.com geo.yieldify.com mw.thghosting.com bat.bing.com; font-src 'self' data: *.midphase.com http://script.hotjar.com https://script.hotjar.com *.puzzel.com fonts.gstatic.com maxcdn.bootstrapcdn.com stats.g.doubleclick.net; default-src 'self' 'unsafe-inline' 'unsafe-eval' *.midphase.com *.puzzel.com; frame-ancestors 'self';
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Consider adding 'preload' to HSTS for maximum security
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
1 headers
Connection
Performance
keep-alive
Caching Headers
0 headers
No caching headers found
Content Headers
2 headers
Content-Length
Content
172
Content-Type
Content
text/html
Server Headers
1 headers
Server
Server
nginx
CORS Headers
0 headers
No CORS headers found
Cookies Headers
0 headers
No cookies headers found
Other Headers
4 headers
Date
Other
Wed, 19 Nov 2025 22:41:44 GMT
Public-Key-Pins
Other
pin-sha256="uGS6BryHyqwUpmtO9athvdOwh1ZdySZSe8Oy34kyG4g="; pin-sha256="JRWVeBVjpju4yD/EXkJEWHsnvbMQyGXB6pxtso/cxFc="; pin-sha256="lSqtN6dwHBqe1uOqlikc88l8EYCVFKT6B6Fn/R10XaE="; pin-sha256="k1VdmcuPhxuKBBlU+7lRo8R7ElgwWLVcdF/lu309/VI="; pin-sha256="EskfQgb+D292n2yh0A286/CkG5omOaRB+R4GiMRMzb8="; pin-sha256="B5PQ6z60woVtbvhTda4HV2V2lZuWO/Fs9nPbZh58zNI="; max-age=5184000;
Www-Authenticate
Other
Basic realm="MP UAT"
X-Robots-Tag
Other
noindex, follow
Recommendations
Enable compression (gzip/brotli) to improve performance
Add Cache-Control header to optimize caching
Analysis completed in 363ms