26 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31536000
Content-Security-Policy
Weak
upgrade-insecure-requests
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Good
no-referrer-when-downgrade
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Significantly strengthen CSP directives
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Consider adding Permissions-Policy to control browser features

Performance Headers

2 headers
Connection
Performance
close
Transfer-Encoding
Performance
chunked

Caching Headers

2 headers
Cache-Control
Caching
no-store, no-cache, must-revalidate
Last-Modified
Caching
Thu, 29 Jan 2026 20:46:33 GMT

Content Headers

1 headers
Content-Type
Content
text/html; charset=UTF-8

Server Headers

1 headers
Server
Server
cloudflare

CORS Headers

0 headers
No CORS headers found

Cookies Headers

1 headers
Set-Cookie
Cookies
_cfuvid=f.wEj6SQstZI3lGM4oLSombcuMKlM2zVC_GaiRNzJTw-1769733575132-0.0.1.1-604800000; path=/; domain=.www.xponential.plus; HttpOnly; Secure; SameSite=None

Other Headers

16 headers
Alt-Svc
Other
h3=":443"; ma=86400
Cf-Ray
Other
9c5ce9bc5c6be5fe-IAD
Date
Other
Fri, 30 Jan 2026 00:39:35 GMT
Edge-Cache-Tag
Other
CT-122137279563,P-6406677,L-100874695821,L-122139178327,L-132172555167,L-149641206344,W-100746815673,W-1645187448225,W-1661278888111,W-1661279143735,W-1682490394883,W-1683010090027,W-1687600787077,W-66595337825,CW-100875770372,CW-101456577330,CW-112818746699,CW-113849218988,CW-122137080918,CW-149642939051,CW-20773788582,CW-66580841278,CW-66594507939,CW-82748850252,CW-82749286509,CW-82752309177,E-100746449686,E-131310981688,E-205592620679,E-37435917256,E-61365502106,E-65291315759,E-66576826893,E-87930039927,MENU-100746815673,PGS-ALL,SW-2,GC-101035089168,GC-136208652565,GC-149642939785
Link
Other
</hs/hsstatic/jquery-libs/static-1.1/jquery/jquery-1.7.1.js>; rel=preload; as=script,<https://api.tiles.mapbox.com/mapbox-gl-js/v0.54.0/mapbox-gl.css>; rel=preload; as=style,<https://use.fontawesome.com/releases/v5.6.3/css/all.css>; rel=preload; as=style,<https://api.mapbox.com/mapbox-gl-js/plugins/mapbox-gl-geocoder/v4.2.0/mapbox-gl-geocoder.css>; rel=preload; as=style,<https://cdnjs.cloudflare.com/ajax/libs/slick-carousel/1.9.0/slick.min.css>; rel=preload; as=style,<https://www.xponential.plus/hubfs/hub_generated/module_assets/1/82752309177/1742938957126/module_Header_Stripe_Button_-_With_CTA_Option.min.css>; rel=preload; as=style,<https://www.xponential.plus/hubfs/hub_generated/template_assets/1/205592620679/1769034265047/template_clarity_tracking_xplus.min.js>; rel=preload; as=script,<//7052064.fs1.hubspotusercontent-na1.net/hubfs/7052064/hub_generated/template_assets/DEFAULT_ASSET/1769718740250/template_layout.min.css>; rel=preload; as=style
Nel
Other
{"success_fraction":0.01,"report_to":"cf-nel","max_age":604800}
Report-To
Other
{"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=MRAyRfxT3CvK2Nr7mAeHFVAiZ4f9dsWQ5GjPYktZ2ZUIVtY8mIJJgNKmW64qVcCK3FtD5m8l3TkxbH7li9RwKL%2BQ2EqS29xpzC80p9GCWAHpKkEyK5mfUxnR1LNnK39CCuVv37Q%3D"}],"group":"cf-nel","max_age":604800}
X-Hs-Cache-Config
Other
BrowserCache-0s-EdgeCache-0s
X-Hs-Cache-Control
Other
s-maxage=36000, max-age=0
X-Hs-Cf-Cache-Status
Other
HIT
X-Hs-Cfworker-Meta
Other
{"contentType":"SITE_PAGE","resolver":"PreRenderedContentResolver"}
X-Hs-Content-Campaign-Id
Other
fb9bc323-776d-4985-b727-d686b6b29598
X-Hs-Content-Id
Other
122137279563
X-Hs-Hub-Id
Other
6406677
X-Hs-Portal-Id
Other
6406677
X-Hs-Prerendered
Other
Thu, 29 Jan 2026 20:46:33 GMT

Recommendations

Enable compression (gzip/brotli) to improve performance