Open
Cached
·
just now
23
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Excellent
max-age=31536000; includeSubDomains; preload
Content-Security-Policy
Basic
frame-ancestors; frame-src; default-src; +10 more
frame-ancestors 'self'; frame-src 'self' blob: data: https://wp-rocket.me/ https://youtube.com https://www.youtube.com https://www.youtube-nocookie.com https://player.vimeo.com *.verso.de *.hsforms.net *.hubspot.com *.hs-sites.com *.hubspot.net play.hubspotvideo.com *.hsforms.com https://bid.g.doubleclick.net https://td.doubleclick.net https://www.googletagmanager.com https://googletagmanager.com; default-src 'none'; script-src 'self' *.verso.de *.wpenginepowered.com https://*.outbrain.com https://amplify.outbrain.com *.hsforms.net *.hubspot.com *.hsadspixel.net *.hs-analytics.net js.hscta.net static.hsappstatic.net *.usemessages.com *.hs-banner.com *.hubspot.net *.hscollectedforms.net *.hsleadflows.net *.hsforms.com *.hs-scripts.com *.hubspotfeedback.com feedback.hubapi.com data: 'unsafe-eval' 'unsafe-inline' https://googletagmanager.com https://tagmanager.google.com https://*.googletagmanager.com https://www.google-analytics.com https://ssl.google-analytics.com https://www.googleadservices.com https://www.google.com https://googleads.g.doubleclick.net https://dntfctn.com https://cdn.mxpnl.com https://snap.licdn.com https://yoast.com https://ams.wpml.org https://*.mixpanel.com https://api-js.mixpanel.com; connect-src 'self' *.verso.de *.wpenginepowered.com https://*.outbrain.com https://stats.g.doubleclick.net https://px.ads.linkedin.com *.dntfctn.com https://dntfctn.com https://*.dntfctn.com *.hubapi.com js.hscta.net *.hubspot.com *.hs-banner.com *.hscollectedforms.net *.hsforms.com https://googleads.g.doubleclick.net https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://www.google-analytics.com https://analytics.google.com https://www.google.com https://yoast.com https://my.yoast.com https://ams.wpml.org https://*.mixpanel.com https://api-js.mixpanel.com https://*.hsappstatic.net; img-src 'self' blob: data: https: *.gravatar.com *.hsforms.net js.hscta.net no-cache.hubspot.com *.hubspot.com *.hubspot.net cdn2.hubspot.net *.hsforms.com www.googletagmanager.com https://googletagmanager.com https://ssl.gstatic.com https://www.gstatic.com https://*.google-analytics.com https://*.googletagmanager.com https://www.google-analytics.com https://googleads.g.doubleclick.net https://www.google.com https://google.com; style-src 'self' 'unsafe-inline' cdn2.hubspot.net *.verso.de https://googletagmanager.com https://tagmanager.google.com https://fonts.googleapis.com https://ams.wpml.org; font-src 'self' https://fonts.gstatic.com data:; object-src 'none'; base-uri 'self'; form-action 'self' https://forms.hsforms.com; media-src 'self'; child-src 'self' blob: *.hsforms.com *.verso.de https://verso.de;
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
no-referrer
Permissions-Policy
Present
accelerometer=(), autoplay=(self), camera=(), encrypted-media=(), fullscreen=(), geolocation=(self), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(self), usb=()
Recommendations
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
Performance Headers
3 headers
Connection
Performance
close
Transfer-Encoding
Performance
chunked
Vary
Performance
Accept-Encoding,Cookie
Caching Headers
1 headers
Cache-Control
Caching
max-age=600, must-revalidate
Content Headers
1 headers
Content-Type
Content
text/html; charset=UTF-8
Server Headers
2 headers
Server
Server
cloudflare
X-Powered-By
Server
WP Engine
CORS Headers
0 headers
No CORS headers found
Cookies Headers
1 headers
Set-Cookie
Cookies
__cf_bm=Vi33tEt4YIVoffaavJe94BqNZVGi69HC6oEcJF7ZE6s-1767016988-1.0.1.1-TgNz._T0P7xGbRGH6HNAPOP_lQpwSghuJNjGqhStbqNry.Inv7gva0CzY6534gjTo8sQFTqlFKFCNXLeLsJgh4eFP4YmYbaEQ_s6xcjeFZg; path=/; expires=Mon, 29-Dec-25 14:33:08 GMT; domain=.verso.de; HttpOnly; Secure; SameSite=None
Other Headers
8 headers
Alt-Svc
Other
h3=":443"; ma=86400
Cf-Cache-Status
Other
DYNAMIC
Cf-Ray
Other
9b59d6d28a87e6f2-IAD
Date
Other
Mon, 29 Dec 2025 14:03:08 GMT
Link
Other
<https://verso.de/>; rel=shortlink
X-Cache
Other
HIT: 3
X-Cache-Group
Other
normal
X-Cacheable
Other
SHORT
Recommendations
Enable compression (gzip/brotli) to improve performance
Consider removing X-Powered-By header to hide server technology
Analysis completed in 506ms