Open
Cached
·
just now
21
Headers
Detected Technologies from Headers
Adobe Fonts (Typekit)
Azure Blob Storage
Bing
Facebook
Font Awesome
GitHub
Google API JS Client
Google DoubleClick
Google Search
Google Tag Manager
HubSpot
Active incidents
HubSpot Forms
Active incidents
jsDelivr
LinkedIn
Microsoft Clarity
Mutiny
Next.js
OneTrust
Optimizely
Reddit
Sanity
6sense
Vercel
Wistia
HTTP Security Headers
Status
Strict-Transport-Security
Excellent
max-age=63072000; includeSubDomains; preload
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Accept-Ranges
bytes
Connection
close
Vary
rsc, next-router-state-tree, next-router-prefetch, next-router-segment-prefetch
accept-ranges: bytes connection: close vary: rsc, next-router-state-tree, next-router-prefetch, next-router-segment-prefetch
Caching Headers
Age
4226
Cache-Control
public, max-age=0, must-revalidate
Etag
"4d432d3595b255a134e2fb6668c843bd"
age: 4226 cache-control: public, max-age=0, must-revalidate etag: "4d432d3595b255a134e2fb6668c843bd"
Content Headers
Content-Disposition
inline
Content-Length
862267
Content-Type
text/html; charset=utf-8
content-disposition: inline content-length: 862267 content-type: text/html; charset=utf-8
CORS Headers
Access-Control-Allow-Origin
*
access-control-allow-origin: *
Cookies Headers
Other Headers
Date
Fri, 01 May 2026 20:28:40 GMT
X-Matched-Path
/
date: Fri, 01 May 2026 20:28:40 GMT x-matched-path: / x-nextjs-prerender: 1 x-nextjs-stale-time: 300 x-vercel-cache: HIT x-vercel-id: iad1::6rm7d-1777667320300-81c5940bcb02
Recommendations
Enable compression (gzip/brotli) to improve performance