Open
Cached
·
just now
19
Headers
Detected Technologies from Headers
Amplitude
AWS CloudFront
Cloudinary
Cookiebot
Facebook
Google AdSense
Google Analytics
Google API JS Client
Google DoubleClick
Google Fonts
Google Search
Google Static File Front End
Google Tag Manager
Hotjar
jsDelivr
LinkedIn
Nginx
OptinMonster
Prismic
Typeform
unpkg
YouTube
Google Cloud
Next.js
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=15552000
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
Vary
Accept-Encoding
connection: close vary: Accept-Encoding
Caching Headers
Age
1636
Cache-Control
s-maxage=31536000, stale-while-revalidate
Etag
"pvn7c5ju2t56qy"
age: 1636 cache-control: s-maxage=31536000, stale-while-revalidate etag: "pvn7c5ju2t56qy"
Content Headers
Content-Length
242526
Content-Type
text/html; charset=utf-8
content-length: 242526 content-type: text/html; charset=utf-8
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Date
Fri, 01 May 2026 16:20:09 GMT
X-Lang
en-us
X-Middleware-Rewrite
/en-us/
date: Fri, 01 May 2026 16:20:09 GMT via: 1.1 6e44ac4753bea102fe3aae286f68acfe.cloudfront.net (CloudFront) x-amz-cf-id: PLr6fvv7OB5jhNL4jo_ypcuaTXRCMXsSTqdPCgys31QbhrqC3gbBYw== x-amz-cf-pop: IAD55-P1 x-cache: Hit from cloudfront x-lang: en-us x-middleware-rewrite: /en-us/ x-nextjs-cache: HIT
Recommendations
Enable compression (gzip/brotli) to improve performance