Open
Cached
·
just now
20
Headers
Detected Technologies from Headers
AWS CloudFront
YouTube
Google Tag Manager
Amazon Advertising
Google Hosted Libraries
Reddit
Yahoo
HubSpot Forms
Azure Blob Storage
Google DoubleClick
Google Analytics
Microsoft Advertising
Adalyser
Mixpanel
New Relic
Cloudflare CDN
Active incidents
Google Cloud Storage
Google Static File Front End
Next.js
Google Fonts
Twitter
Hotjar
LinkedIn
Singular
Cloudflare Turnstile
Google Search
Navattic
Google Cloud Functions
Facebook
Decagon
Amazon S3
Cloudflare CDNJS
Active incidents
AWS
SpeedCurve
HubSpot
Quora
The Trade Desk
Google Cloud
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Present
ch-ua-model=("https://sdk-api-v1.singular.net"), ch-ua-platform-version=("https://sdk-api-v1.singular.net"), ch-ua-full-version-list=("https://sdk-api-v1.singular.net")
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
Performance Headers
Connection
close
Transfer-Encoding
chunked
Vary
Accept-Encoding
connection: close transfer-encoding: chunked vary: Accept-Encoding
Caching Headers
Cache-Control
private, no-cache, no-store, max-age=0, must-revalidate
Etag
W/"zgztp05jwirdue"
cache-control: private, no-cache, no-store, max-age=0, must-revalidate etag: W/"zgztp05jwirdue"
Content Headers
Content-Type
text/html; charset=utf-8
content-type: text/html; charset=utf-8
Server Headers
server: cloudflare x-powered-by: Next.js
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Accept-Ch
Sec-CH-UA-Platform-Version, Sec-CH-UA-Arch, Sec-CH-UA-Model, Sec-CH-UA-Bitness
Alt-Svc
h3=":443"; ma=86400
Date
Wed, 29 Apr 2026 09:07:59 GMT
X-Download-Options
noopen
accept-ch: Sec-CH-UA-Platform-Version, Sec-CH-UA-Arch, Sec-CH-UA-Model, Sec-CH-UA-Bitness alt-svc: h3=":443"; ma=86400 cf-cache-status: DYNAMIC cf-ray: 9f3d28d4ab71d6fd-IAD date: Wed, 29 Apr 2026 09:07:59 GMT x-download-options: noopen
Recommendations
Enable compression (gzip/brotli) to improve performance
Consider removing X-Powered-By header to hide server technology