carlsgolfland.com | Analytics by SecurityHeaders

HTTP Headers report for carlsgolfland.com

Header Name Header Data
HTTP status code 200
X-Xss-Protection 1
Accept-Ranges bytes
X-Magento-Cache-Debug HIT
Date Sun, 20 Apr 2025 18:37:40 GMT
Access-Control-Allow-Headers X-Requested-With
X-Content-Type-Options nosniff
X-Frame-Options SAMEORIGIN
Vary Accept-Encoding
Expires -1
Cache-Control no-store, no-cache, must-revalidate, max-age=0
Access-Control-Allow-Methods GET, HEAD
Access-Control-Allow-Origin *
Strict-Transport-Security max-age=31557600
Via 1.1 varnish-75d9bb777d-fp7hr (Varnish/7.2)
Content-Type text/html; charset=UTF-8
Connection keep-alive
Content-Security-Policy script-src 'self' 'unsafe-eval' 'unsafe-inline' *.searchspring.net seoab.io *.cloudmaestro.com *.googleapis.com *.nr-data.net *.pcapredict.com carlsgolf.resultspage.com carlsgolf.resultsdemo.com *.bronto.com *.userway.org *.cloudflare.com container.pepperjam.com *.newrelic.com *.carlsgolfland.com sealserver.trustwave.com *.yotpo.com usrwy.com *.google.com www.googleoptimize.com www.gstatic.com *.rackcdn.com bat.bing.com *.sli-spark.com *.facebook.net *.doubleclick.net *.hotjar.com *.appspot.com www.google-analytics.com www.googleadservices.com www.googletagmanager.com *.signifyd.com *.paypal.com www.paypalobjects.com js.authorize.net js.braintreegateway.com services.postcodeanywhere.co.uk *.resultspage.com secure.wufoo.com widget.modernretail.com www.trustedsite.com g.microsoft.com cdn.ywxi.net static.wufoo.com web-assets.stylitics.com assets.adobedtm.com apps.golfstixvalueguide.com apps.bazaarvoice.com c.tvpixel.com srd.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com mpsnare.iesnare.com www.smarterlessons.com *.bazaarvoice.com www.ascendpartner.com polaris.truevaultcdn.com convertexperiences.com *.convertexperiments.com www.youtube.com/iframe_api www.youtube.com/s/player/9d15588c/www-widgetapi.vflset/www-widgetapi.js www.youtube.com rp.liadm.com rp4.liadm.com idx.liadm.com d-code.liadm.com i.liadm.com *.listrakbi.com *.listrak.com *.online-metrix.net h64.online-metrix.net recscont.listrakbi.com s.listrakbi.com s1.listrakbi.com s2.listrakbi.com sca1.listrakbi.com sca2.listrakbi.com st.listrakbi.com product.listrakbi.com oc.listrakbi.com cdn.listrakbi.com at1.listrakbi.com al1.listrakbi.com recs.listrakbi.com onescript-recscont.listrakbi.com m1.listrakbi.com idx.listrakbi.com bl.listrakbi.com barcode.listrakbi.com da1.listrakbi.com fp.listrakbi.com webhooks.listrakbi.com cntrecsprd.listrakbi.com 2ndswing.com https://www.clarity.ms/ https://cdn1.affirm.com/js/v2/affirm.js cdn.noibu.com *.noibu.com; report-uri /.webscale/csp-report
Content-Security-Policy-Report-Only font-src *.fontawesome.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com api.bazaarvoice.com stg.api.bazaarvoice.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.affirm.com *.affirm.ca display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.affirm.com *.affirm.ca display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.affirm.com *.affirm.ca apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.avada.io *.cloudflare.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com display.ugc.bazaarvoice.com unsafe-inline assets.braintreegateway.com *.fontawesome.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.affirm.com *.affirm.ca api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com api.addressy.com https://get.geojs.io *.avada.io https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline';
Section-Io-Tag Hit
Grace none
Pragma no-cache
Section-Io-Id d37feb0c492fb2d518146208816d1f32

About the tool

By using SecurityHeaders.info, you can quickly identify missing or misconfigured headers and take steps to secure your website, improving both security and user confidence.

This tool is widely used by developers, security professionals, and organizations to ensure their websites adhere to best practices in web security.

We also have another analytic tool that is used for identifying popularity metrics, general information about the business, finding similar products and competitors, and much more.

Watch it now at TrustRadar