Open
Cached
·
just now
13
Headers
Detected Technologies from Headers
Microsoft Advertising
Cookiebot
Facebook
Freshdesk
Google AdSense
Google Analytics
Google DoubleClick
Google Fonts
Google Search
Google Static File Front End
Google Tag Manager
Hotjar
HubSpot
HubSpot Analytics
HubSpot Forms
Iubenda
LinkedIn
Nginx
PHP
Trustpilot
Google Cloud
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000; preload
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
Transfer-Encoding
chunked
connection: close transfer-encoding: chunked
Caching Headers
Cache-Control
no-store, no-cache, must-revalidate
Expires
Thu, 19 Nov 1981 08:52:00 GMT
Pragma
no-cache
cache-control: no-store, no-cache, must-revalidate expires: Thu, 19 Nov 1981 08:52:00 GMT pragma: no-cache
Content Headers
Content-Type
text/html; charset=UTF-8
content-type: text/html; charset=UTF-8
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Date
Thu, 03 Sep 2026 07:54:59 GMT
date: Thu, 03 Sep 2026 07:54:59 GMT
Recommendations
Enable compression (gzip/brotli) to improve performance