Open
Cached
·
just now
13
Headers
Detected Technologies from Headers
Auth0
Google Tag Manager
Amplitude
PartnerStack
Fullstory
Statuspage
Envoy
Google DoubleClick
Google Analytics
Crazy Egg
Dropbox
Segment
Typeform
LaunchDarkly
Next.js
Calendly
TikTok Analytics
Google Fonts
Wistia
Twitter
LinkedIn
Active incidents
Zendesk
Contentful
Stripe
Pexels
Facebook
Amazon S3
StackAdapt
OneTrust
Rollbar
AWS
Akamai
Active incidents
Quora
Optimizely
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy-Report-Only
Basic
report-uri; block-all-mixed-content; default-src; +10 more
Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
Vary
Accept-Encoding
connection: close vary: Accept-Encoding
Caching Headers
Cache-Control
private, no-cache, no-store, max-age=0, must-revalidate
Etag
"tszej4sbg74h8v"
cache-control: private, no-cache, no-store, max-age=0, must-revalidate etag: "tszej4sbg74h8v"
Content Headers
Content-Length
209060
Content-Type
text/html; charset=utf-8
content-length: 209060 content-type: text/html; charset=utf-8
Server Headers
server: istio-envoy x-powered-by: Next.js
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
date: Thu, 02 Apr 2026 13:29:29 GMT x-envoy-upstream-service-time: 73
Recommendations
Enable compression (gzip/brotli) to improve performance
Consider removing X-Powered-By header to hide server technology