SSL Verification Bypassed
The server's SSL certificate could not be verified. The analysis was completed using insecure mode. Data may be less reliable.
Reason:
Expired Certificate - the server's certificate has expired
Open
Cached
·
just now
18
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000
Content-Security-Policy
Basic
script-src; worker-src; frame-src; +4 more
script-src 'unsafe-eval' 'unsafe-inline' 'self' *.openai.com chatgpt.com *.donal-tobin.workers.dev *.immagnify.com www.google.com www.gstatic.com *.upvert.io *.upvertcdn.io *.liadm.com *.usbrowserspeed.com *.getwarmly.com *.datashopper.com *.hubspot.com *.sentry-cdn.com *.cloudflare.com *.googleapis.com *.apollo.io *.redditstatic.com *.gstatic.com *.wistia.com *.termly.io *.unifyintent.com *.calendly.com *.adroll.com *.whattime.co.kr *.amazonaws.com *.referralcandy.com *.doubleclick.net *.clearbitscripts.com *.arcade.software *.clarity.ms *.clearbitjs.com *.capterra.com *.facebook.net *.googletagmanager.com *.hs-scripts.com *.licdn.com *.woopra.com *.ads-twitter.com *.youtube.com *.hotjar.com *.hsforms.net *.hs-analytics.net *.hs-banner.com *.hsadspixel.net *.hscollectedforms.net *.bing.com *.google-analytics.com *.g2crowd.com *.autopilothq.com *.mxpnl.com *.chilipiper.com *.googleadservices.com *.clickcease.com *.intercomcdn.com *.intercom.io *.visualwebsiteoptimizer.com app.vwo.com cdn.pushcrew.com; worker-src 'self' blob:; frame-src www.google.com www.gstatic.com app.vwo.com whattime.co.kr calendly.com *.liadm.com *.adroll.com *.doubleclick.net *.youtube.com *.facebook.com *.hsforms.com *.chilipiper.com *.arcade.software *.googletagmanager.com *.visualwebsiteoptimizer.com; default-src https: wss: data: 'unsafe-inline' ; object-src 'none'; frame-ancestors 'none' ; media-src 'self' blob: https:
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Present
geolocation=()
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
Performance Headers
1 headers
Connection
Performance
close
Caching Headers
2 headers
Etag
Caching
"1c872d976584de7ecb51b555b58f4922"
Last-Modified
Caching
Wed, 21 Jan 2026 09:23:21 GMT
Content Headers
2 headers
Content-Length
Content
147198
Content-Type
Content
text/html
Server Headers
1 headers
Server
Server
AmazonS3
CORS Headers
0 headers
No CORS headers found
Cookies Headers
0 headers
No cookies headers found
Other Headers
6 headers
Date
Other
Thu, 22 Jan 2026 03:41:05 GMT
Via
Other
1.1 b8682e9104d4ce1d04554da301dc9d64.cloudfront.net (CloudFront)
X-Amz-Cf-Id
Other
_LYYtfcHZeUNIN6g9dOQA7dMU7lK1D2Duizo7eWeix8eWPXRBlVhSA==
X-Amz-Cf-Pop
Other
IAD55-P4
X-Amz-Version-Id
Other
3ABpDkHK2p5VInnOL_w6ISBWPBj1pufv
X-Cache
Other
Miss from cloudfront
Recommendations
Enable compression (gzip/brotli) to improve performance
Add Cache-Control header to optimize caching