Open
Cached
·
just now
15
Headers
Detected Technologies from Headers
AWS CloudFront
Google AdSense
Google Maps
Google Tag Manager
Spotify
Reddit
DataTables
Trustpilot
Google DoubleClick
Google Analytics
Microsoft Advertising
Segment
Cloudflare CDN
Datadog
Google Static File Front End
LaunchDarkly
Outbrain
TikTok Analytics
Google Fonts
Twitter
Quantcast
Hotjar
Kustomer
LinkedIn
Contentful
Stripe
Google Search
BootstrapCDN
Cloudflare
Active incidents
Facebook
OneTrust
Adobe Fonts (Typekit)
Heap
Cloudflare CDNJS
jQuery
Quora
YouTube
Microsoft Clarity
Font Awesome
jsDelivr
Google Cloud
Google Cloud Storage
Express
HTTP Security Headers
Status
Strict-Transport-Security
Excellent
max-age=31536000; includeSubDomains; preload
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
Transfer-Encoding
chunked
connection: close transfer-encoding: chunked
Caching Headers
Cache-Control
public, max-age=1800
cache-control: public, max-age=1800
Content Headers
Content-Type
text/html; charset=utf-8
content-type: text/html; charset=utf-8
Server Headers
server: cloudflare x-powered-by: Express
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Date
Sat, 02 May 2026 23:16:33 GMT
Reporting-Endpoints
csp-reporting-endpoint="https://csp-report.browser-intake-datadoghq.eu/api/v2/logs?dd-api-key=pubd4258020965cc5258eee35ac618e9586&dd-evp-origin=content-security-policy&ddsource=csp-report"
X-Ssr-Cache
redis, age: 13m 22s
cf-cache-status: DYNAMIC cf-ray: 9f5abbfa98f1c97f-IAD date: Sat, 02 May 2026 23:16:33 GMT reporting-endpoints: csp-reporting-endpoint="https://csp-report.browser-intake-datadoghq.eu/api/v2/logs?dd-api-key=pubd4258020965cc5258eee35ac618e9586&dd-evp-origin=content-security-policy&ddsource=csp-report" x-ssr-cache: redis, age: 13m 22s
Recommendations
Enable compression (gzip/brotli) to improve performance
Consider removing X-Powered-By header to hide server technology