Open
Cached
·
just now
19
Headers
Detected Technologies from Headers
AWS CloudFront
Google AdSense
Chili Piper
Google Maps
Microsoft 365
Google Tag Manager
Bing
G2
Salesforce Cloud
Amplitude
Affirm
Mux
Google Translate
Reddit
hCaptcha
Webflow
Statuspage
HubSpot Forms
Adyen
Google DoubleClick
Google Pay
Google Analytics
Microsoft Advertising
GIPHY
Google Static File Front End
Calendly
Google API JS Client
TikTok Analytics
AzureFrontDoor
Osano
LinkedIn
Zendesk
Microsoft ASP.NET CDN
Hygraph
Cloudflare Turnstile
LiveChat
Stripe
HubSpot Analytics
unpkg
Google Search
BootstrapCDN
Imperva
Adobe Marketo
Apple Pay
Apple ID
Facebook
Instagram
Adobe Fonts (Typekit)
Pinterest
Cloudflare CDNJS
TikTok
jQuery
Vimeo
ipify
HubSpot
YouTube
Microsoft Clarity
Font Awesome
Sentry
jsDelivr
Google Cloud
Microsoft Azure
HTTP Security Headers
Status
Strict-Transport-Security
Excellent
max-age=63072000; includeSubDomains; preload
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
Transfer-Encoding
chunked
connection: close transfer-encoding: chunked
Caching Headers
Cache-Control
private
cache-control: private
Content Headers
Content-Type
text/html; charset=utf-8
content-type: text/html; charset=utf-8
Server Headers
No server headers found
CORS Headers
Access-Control-Allow-Headers
accept, content-type
Access-Control-Allow-Methods
*
Access-Control-Allow-Origin
https://api.vagaro.com
Access-Control-Expose-Headers
Request-Context
access-control-allow-headers: accept, content-type access-control-allow-methods: * access-control-allow-origin: https://api.vagaro.com access-control-expose-headers: Request-Context
Cookies Headers
Other Headers
Date
Fri, 10 Apr 2026 15:29:31 GMT
Request-Context
appId=cid-v1:54764664-9433-4dc2-9ca7-e743d604b31f
X-Iinfo
13-40411599-40411600 NNNY CT(12 13 0) RT(1775834971197 13) q(0 0 0 0) r(0 9) U12
X-Server-Hpvmssus03-Path
Public_Web_Backend
date: Fri, 10 Apr 2026 15:29:31 GMT request-context: appId=cid-v1:54764664-9433-4dc2-9ca7-e743d604b31f x-cdn: Imperva x-iinfo: 13-40411599-40411600 NNNY CT(12 13 0) RT(1775834971197 13) q(0 0 0 0) r(0 9) U12 x-server-hpvmssus03-path: Public_Web_Backend
Recommendations
Enable compression (gzip/brotli) to improve performance