Open
Cached
·
just now
13
Headers
Detected Technologies from Headers
Auth0
Google Tag Manager
Amplitude
PartnerStack
Fullstory
Statuspage
Envoy
Google DoubleClick
Google Analytics
Crazy Egg
Dropbox
Segment
Typeform
LaunchDarkly
Next.js
Calendly
TikTok Analytics
Google Fonts
Wistia
Twitter
LinkedIn
Zendesk
Contentful
Stripe
Pexels
Facebook
Amazon S3
StackAdapt
OneTrust
Rollbar
AWS
Akamai
Quora
Optimizely
Active incidents
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy-Report-Only
Basic
report-uri; block-all-mixed-content; default-src; +10 more
Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
Vary
Accept-Encoding
connection: close vary: Accept-Encoding
Caching Headers
Cache-Control
private, no-cache, no-store, max-age=0, must-revalidate
Etag
"tszej4sbg74h8v"
cache-control: private, no-cache, no-store, max-age=0, must-revalidate etag: "tszej4sbg74h8v"
Content Headers
Content-Length
209060
Content-Type
text/html; charset=utf-8
content-length: 209060 content-type: text/html; charset=utf-8
Server Headers
server: istio-envoy x-powered-by: Next.js
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
date: Mon, 30 Mar 2026 21:15:48 GMT x-envoy-upstream-service-time: 74
Recommendations
Enable compression (gzip/brotli) to improve performance
Consider removing X-Powered-By header to hide server technology