Open
Cached
·
just now
23
Headers
Detected Technologies from Headers
AWS CloudFront
AWS
Amazon S3
Calendly
Cloudflare CDN
Cloudflare CDNJS
Font Awesome
Google AdSense
Google Analytics
Google API JS Client
Google DoubleClick
Google Search
Google Static File Front End
Google Tag Manager
Hotjar
HubSpot
HubSpot Analytics
HubSpot Forms
IP-API
jsDelivr
LinkedIn
Sentry
Vimeo
Wistia
Yoast
Google Cloud
HTTP Security Headers
Status
Strict-Transport-Security
Good
max-age=63072000; includeSubDomains
X-Frame-Options
Present
SAMEORIGIN, SAMEORIGIN
X-Content-Type-Options
Present
nosniff, nosniff
Referrer-Policy
Present
strict-origin-when-cross-origin, strict-origin-when-cross-origin
Permissions-Policy
Present
accelerometer=(), autoplay=(), camera=(); +11 more
Recommendations
- • Consider adding 'preload' to HSTS for maximum security
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
Performance Headers
Connection
close
Transfer-Encoding
chunked
Vary
Accept-Encoding, Accept-Encoding, Accept-Encoding, Accept-Encoding
connection: close transfer-encoding: chunked vary: Accept-Encoding, Accept-Encoding, Accept-Encoding, Accept-Encoding
Caching Headers
Cache-Control
max-age=600, must-revalidate
cache-control: max-age=600, must-revalidate
Content Headers
Content-Type
text/html; charset=UTF-8
content-type: text/html; charset=UTF-8
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Alt-Svc
h3=":443"; ma=86400
Date
Mon, 04 May 2026 05:21:37 GMT
X-Cache
HIT: 26
X-Cache-Group
normal
X-Cacheable
SHORT
X-Permitted-Cross-Domain-Policies
none
alt-svc: h3=":443"; ma=86400 cf-cache-status: DYNAMIC cf-ray: 9f651021ee9082f6-IAD date: Mon, 04 May 2026 05:21:37 GMT x-cache: HIT: 26 x-cache-group: normal x-cacheable: SHORT x-permitted-cross-domain-policies: none
Recommendations
Enable compression (gzip/brotli) to improve performance
Consider removing X-Powered-By header to hide server technology