Open
Cached
·
just now
22
Headers
Detected Technologies from Headers
Algolia
AWS CloudFront
Amazon S3
Cloudflare CDNJS
Contentful
Esri
Facebook
Google AdSense
Google Analytics
Google DoubleClick
Google Fonts
Google Optimize
Google Search
Google Tag Manager
HubSpot
Active incidents
HubSpot Analytics
Active incidents
HubSpot CMS
Active incidents
HubSpot Feedback & Surveys
Active incidents
HubSpot Forms
Active incidents
HubSpot Live Chat
Active incidents
HubSpot Video
Active incidents
LinkedIn
Microsoft Clarity
Sketchfab
Twitter
Vimeo
YouTube
HTTP Security Headers
Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
no-referrer
Permissions-Policy
Missing
Not configured
Recommendations
- • Consider adding 'preload' to HSTS for maximum security
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Accept-Ranges
bytes
Connection
close
Vary
Accept-Encoding
accept-ranges: bytes connection: close vary: Accept-Encoding
Caching Headers
Age
1854
Cache-Control
public, max-age=0, must-revalidate
Etag
"5412a91c3c49ffa440a743f063685b85"
Last-Modified
Fri, 01 May 2026 14:52:07 GMT
age: 1854 cache-control: public, max-age=0, must-revalidate etag: "5412a91c3c49ffa440a743f063685b85" last-modified: Fri, 01 May 2026 14:52:07 GMT
Content Headers
Content-Length
177468
Content-Type
text/html
content-length: 177468 content-type: text/html
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Date
Sat, 02 May 2026 16:37:39 GMT
X-Permitted-Cross-Domain-Policies
none
date: Sat, 02 May 2026 16:37:39 GMT via: 1.1 b30e8d5c8b76c102ed260379b18e1d52.cloudfront.net (CloudFront) x-amz-cf-id: kbG5C-Ld_lCCfIKOKyj9jHwO45GJfGqJnY9Kvh4kWi72slrWiga_rw== x-amz-cf-pop: IAD55-P6 x-amz-server-side-encryption: AES256 x-cache: Hit from cloudfront x-permitted-cross-domain-policies: none
Recommendations
Enable compression (gzip/brotli) to improve performance