Open Cached · just now
30 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Weak
frame-ancestors
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Significantly strengthen CSP directives
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

Performance Headers

3 headers
Connection
Performance
close
Transfer-Encoding
Performance
chunked
Vary
Performance
Accept-Encoding

Caching Headers

1 headers
Cache-Control
Caching
public, max-age=0, s-maxage=3600

Content Headers

1 headers
Content-Type
Content
text/html; charset=UTF-8

Server Headers

1 headers
Server
Server
cloudflare

CORS Headers

4 headers
Access-Control-Allow-Credentials
Cors
true
Access-Control-Allow-Headers
Cors
Origin, Content-Type, X-Auth-Token,authorization,XMLHttpRequest, user-agent, accept, x-requested-with
Access-Control-Allow-Methods
Cors
GET, POST, PATCH, PUT, DELETE, OPTIONS, READ
Access-Control-Allow-Origin
Cors
*

Cookies Headers

1 headers
Set-Cookie
Cookies
__cf_bm=Np06S7Il4USm84t7Z3kMfFBJRPVVJ5ks.GY_dFTK8PI-1765011697-1.0.1.1-mTlzlp0vDh4RrHiYqWXcATIMIMtaNNRQKc0pI8_CC9tlck7cuC6geDph5.78z8TWS_Td2YpsUJKM9JdCANEKfxyUNesDJT20jV2s7WUFB7k; path=/; expires=Sat, 06-Dec-25 09:31:37 GMT; domain=.zoodirect.com; HttpOnly; Secure; SameSite=None

Other Headers

16 headers
Alt-Svc
Other
h3=":443"; ma=86400
Cache-Tag
Other
79840c91-7559-40bc-93eb-388b97a66829,e06c959e92696befb6247367fc716c367e971b0912c4e1c609264db7f173eecf
Cf-Cache-Status
Other
MISS
Cf-Ray
Other
9a9a99841f8c07a4-IAD
Date
Other
Sat, 06 Dec 2025 09:01:37 GMT
Ki-Cache-Tag
Other
79840c91-7559-40bc-93eb-388b97a66829,e06c959e92696befb6247367fc716c367e971b0912c4e1c609264db7f173eecf
Ki-Cache-Type
Other
Edge
Ki-Cf-Cache-Status
Other
SAVING
Ki-Edge
Other
v=24.0.0;mv=5.0.18
Ki-Origin
Other
Link
Other
<https://zoodirect.com/wp-json/>; rel="https://api.w.org/", <https://zoodirect.com/wp-json/wp/v2/pages/706>; rel="alternate"; title="JSON"; type="application/json", <https://zoodirect.com/>; rel=shortlink
Nel
Other
{"success_fraction":0.01,"report_to":"cf-nel","max_age":604800}
Report-To
Other
{"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=UbUF2tU5MLJ%2FL0IWbvs1c%2BsL2lj23ykaV0bQ%2FQd1tJAoVwQzK2Phzt%2B97ouMtz2EJZurDq7MdHch2EBxVAfN6lI%2BpN907%2B7e4our2d6U05mElcPtwg%2FEhJeWo%2Ff5UHo%3D"}],"group":"cf-nel","max_age":604800}
X-Content-Security-Policy
Other
script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.paypal.com/ https://*.stripe.com/ https://*.tawk.to/ https://cdn.jsdelivr.net/ https://pixel.wp.com/ https://r.stripe.com/ https://s3.amazonaws.com/ https://stats.wp.com/ https://tawk.link/ https://www.google.com/ https://www.gstatic.com/ https://www.paypal.com/ https://www.paypalobjects.com/ https://www.recaptcha.net/ https://*.goaffpro.com/; img-src 'self' https://www.paypalobjects.com/ https://s3.amazonaws.com/ https://*.tawk.to/ https://tawk.link/ https://s.w.org/ https://pixel.wp.com/ https://*.stripe.com/ https://*.cdninstagram.com/ https://cdn.jsdelivr.net/ https://*.paypal.com/; object-src 'self' https://*.paypal.com/ https://*.stripe.com/ https://www.google.com/ https://*.stripe.com/ https://*.tawk.to/; frame-src 'self' https://*.paypal.com/ https://*.stripe.com/ https://www.google.com/ https://*.stripe.com/ https://*.tawk.to/; form-action 'self' ; worker-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.stripe.com/ https://*.goaffpro.com/ https://zoodirect.com/;
X-Edge-Location-Klb
Other
1
X-Kinsta-Cache
Other
HIT

Recommendations

Enable compression (gzip/brotli) to improve performance

Analysis completed in 399ms