Technical Information
| HTTP Status Code | 403 |
| HTTP Version | HTTP/1.1 |
| HTTPS | ✔ Available |
| IP Address | 172.64.149.225 |
| Server Software | cloudflare |
| CDN | Cloudflare |
| Compression | gzip |
|
🚫 🟡 HTTP 403 Error | The server returned a 403 error. Check the access configuration. |
|
ℹ 🔵 Missing Content Security Policy | CSP is not configured. It helps prevent XSS attacks and content injection. |
HTTP Status Code 403
HTTP Version HTTP/1.1
HTTPS ✔ Available
IP Address 172.64.149.225
Server Software cloudflare
CDN Cloudflare
Compression gzip
🚫 🟡 HTTP 403 Error The server returned a 403 error. Check the access configuration.
ℹ 🔵 Missing Content Security Policy CSP is not configured. It helps prevent XSS attacks and content injection.
Performance
| DNS Lookup | 11.3 ms |
| TCP Connect | 13 ms |
| TLS Handshake | 7 ms |
| Time To First Byte (TTFB) | 56.1 ms |
| Content Download | 7.9 ms |
| Total Response Time | 64 ms |
DNS Lookup 11.3 ms
TCP Connect 13 ms
TLS Handshake 7 ms
Time To First Byte (TTFB) 56.1 ms
Content Download 7.9 ms
Total Response Time 64 ms
Security
| HTTPS | ✔ Enabled |
| HSTS | ✔ max-age=31536000; includeSubDomains |
| CSP | ⚠ Not configured |
| X-Frame-Options | ✔ SAMEORIGIN |
| X-Content-Type-Options | ✔ nosniff |
| Referrer Policy | same-origin |
| Permissions Policy | ✔ Configured |
| HTTP/2 | ⚠ HTTP/1.1 |
HTTPS ✔ Enabled
HSTS ✔ max-age=31536000; includeSubDomains
CSP ⚠ Not configured
X-Frame-Options ✔ SAMEORIGIN
X-Content-Type-Options ✔ nosniff
Referrer Policy same-origin
Permissions Policy ✔ Configured
HTTP/2 ⚠ HTTP/1.1
SEO Quick Check
Title Welcome
Detected Technologies
| Technology | Shopify Google Analytics Cloudflare |
Technology Shopify Google Analytics Cloudflare
HTTP Headers
| Date | Thu, 20 Aug 2026 06:50:14 GMT |
| Content-type | text/html; charset=UTF-8 |
| Accept-ch | Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA |
| Cf-mitigated | challenge |
| X-frame-options | SAMEORIGIN |
| Server | cloudflare |
| Critical-ch | Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA |
| Cross-origin-embedder-policy | require-corp |
| Cross-origin-opener-policy | same-origin |
| Cross-origin-resource-policy | same-origin |
| Origin-agent-cluster | ?1 |
| Permissions-policy | accelerometer=(),camera=(),clipboard-read=(),clipboard-write=(),geolocation=(),gyroscope=(),hid=(),magnetometer=(),microphone=(),payment=(),publickey-credentials-get=(),screen-wake-lock=(),serial=(),sync-xhr=(),usb=(),xr-spatial-tracking=* |
| Referrer-policy | same-origin |
| Server-timing | chlray;desc="a2df766d8fef4e30" |
| X-content-type-options | nosniff |
| Strict-transport-security | max-age=31536000; includeSubDomains |
| Vary | accept-encoding |
| Set-cookie | __cf_bm=Z9eJHapysOwJl07rDiUV4I1awXiP6APds_Eb5nMlSBY-1787208614.0012188-1.0.1.1-wHlWP3o76V.11oJy7YuO4Kn3WqmkX5sZSFJOWP7nSrQBZ.BIAwW3ZuvX5FgAPH2seuexR8CHYgutMe1KEfCuYjUuclN4Jg5I6vXaaKbDIHWYXC8tqgzo0FomylS.tTgU; HttpOnly; SameSite=None; Secure; Path=/; Domain=sofi.com; Expires=Thu, 20 Aug 2026 07:20:14 GMT |
| Report-to | {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=ZKLE4qaRyuTugyJjCCM9ZuPfcqHXdpD7q%2ForVYEx1HvcWcK9e9BVmrqHpXITr2tbpNuz5vIddb%2BWk64DYT82ik85pgHAuyAxXjFjuLINNtm20W1Jkr6BGyJ3"}]} |
| Nel | {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800} |
| Content-encoding | gzip |
| Cf-ray | a2df766d8fef4e30-CDG |
Meta Tags
| Content-Type | text/html; charset=UTF-8 |
| Viewport | width=device-width, initial-scale=1.0, shrink-to-fit=no |
| Refresh | 360 |
Date Thu, 20 Aug 2026 06:50:14 GMT
Content-type text/html; charset=UTF-8
Accept-ch Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA
Cf-mitigated challenge
X-frame-options SAMEORIGIN
Server cloudflare
Critical-ch Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA
Cross-origin-embedder-policy require-corp
Cross-origin-opener-policy same-origin
Cross-origin-resource-policy same-origin
Origin-agent-cluster ?1
Permissions-policy accelerometer=(),camera=(),clipboard-read=(),clipboard-write=(),geolocation=(),gyroscope=(),hid=(),magnetometer=(),microphone=(),payment=(),publickey-credentials-get=(),screen-wake-lock=(),serial=(),sync-xhr=(),usb=(),xr-spatial-tracking=*
Referrer-policy same-origin
Server-timing chlray;desc="a2df766d8fef4e30"
X-content-type-options nosniff
Strict-transport-security max-age=31536000; includeSubDomains
Vary accept-encoding
Set-cookie __cf_bm=Z9eJHapysOwJl07rDiUV4I1awXiP6APds_Eb5nMlSBY-1787208614.0012188-1.0.1.1-wHlWP3o76V.11oJy7YuO4Kn3WqmkX5sZSFJOWP7nSrQBZ.BIAwW3ZuvX5FgAPH2seuexR8CHYgutMe1KEfCuYjUuclN4Jg5I6vXaaKbDIHWYXC8tqgzo0FomylS.tTgU; HttpOnly; SameSite=None; Secure; Path=/; Domain=sofi.com; Expires=Thu, 20 Aug 2026 07:20:14 GMT
Report-to {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=ZKLE4qaRyuTugyJjCCM9ZuPfcqHXdpD7q%2ForVYEx1HvcWcK9e9BVmrqHpXITr2tbpNuz5vIddb%2BWk64DYT82ik85pgHAuyAxXjFjuLINNtm20W1Jkr6BGyJ3"}]}
Nel {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Content-encoding gzip
Cf-ray a2df766d8fef4e30-CDG