21 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Excellent
max-age=63072000; includeSubDomains; preload
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Present
geolocation=(), microphone=(), payment=()
Recommendations
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking

Performance Headers

2 headers
Connection
Performance
close
Transfer-Encoding
Performance
chunked

Caching Headers

4 headers
Cache-Control
Caching
no-store
Etag
Caching
W/"4dabb4424584cc0569f8be4e87bacf14"
Expires
Caching
Fri, 01 Jan 1970 00:00:00 GMT
Pragma
Caching
no-cache

Content Headers

1 headers
Content-Type
Content
text/html; charset=utf-8

Server Headers

2 headers
Server
Server
openresty
X-Runtime
Server
0.800125

CORS Headers

0 headers
No CORS headers found

Cookies Headers

1 headers
Set-Cookie
Cookies
_aha_app_2=xmmkQ7FMZoOutmFDL26MEqfiqLzZV4Tp%2BbhZYaY8tJCLEkvHLfG%2FNkK5UmmcJciafPKoMeOX8MnyypxhACAVVHOI6iX2vRINq0czbiFhuFZLdxmcwq%2ByreiR8uePdmlZlvvLM9PQYoZu0fWCZw1Puo8IrIOQpniKPtmoYxAezPBxAK1OrWliX1Kt7A2OzwhoauQBBw6Z5wu6O6yrOUHYTBy7XD7Ag8iHaLYXrlBz8HpTlikgD23YcvRWCcXqHQEmjQYAp3Bex%2BNqKuPkHbsBYavi--RqG1Z3fd1RCax7r%2B--JcX34v3yYZxqb4dHyj4M2Q%3D%3D; path=/; secure; HttpOnly; SameSite=None

Other Headers

6 headers
Date
Other
Sun, 18 Jan 2026 16:19:04 GMT
Feature-Policy
Other
geolocation 'none'; microphone 'none'; payment 'none'
Link
Other
<https://wishlist.webflow.com/assets/idea_portals-v2-e6ed26f3692f363180c1b5f0fdec4f55.css>; rel=preload; as=style; nopush,<https://wishlist.webflow.com/assets/runtime-v2-20104273a090ccdcb2338bac31a3b61b.js>; rel=preload; as=script; nopush,<https://wishlist.webflow.com/assets/vendor-v2-16d039b5a354d53c1c02493b2a92d909.js>; rel=preload; as=script; nopush,<https://wishlist.webflow.com/assets/idea_portals-v2-72b342884b03633227091d664449905f.js>; rel=preload; as=script; nopush
P3p
Other
CP="Aha! does not have a P3P policy. http://www.aha.io/legal/privacy_policy"
X-Permitted-Cross-Domain-Policies
Other
none
X-Request-Id
Other
7ccdaa6e-1ef4-4b9d-b73b-38d0898e13c0

Recommendations

Enable compression (gzip/brotli) to improve performance