Technical Information
| HTTP Status Code | 200 |
| HTTP Version | HTTP/1.1 |
| HTTPS | ✔ Available |
| IP Address | 192.0.78.229 |
| Server Software | nginx |
| CDN | CDN detected (Server-Timing) |
| Compression | gzip |
|
🔒 🟡 Mixed Content (1 HTTP resources) | The page is served over HTTPS but loads 1 resource(s) over HTTP. This may be blocked in modern browsers. |
|
🕐 🟡 Slow Response (1563 ms) | Response time exceeds 1 second. Consider optimizing the server or using caching. |
|
ℹ 🔵 Missing Content Security Policy | CSP is not configured. It helps prevent XSS attacks and content injection. |
|
ℹ 🔵 Missing X-Frame-Options | The site can be embedded in iframes by third parties (clickjacking risk). |
HTTP Status Code 200
HTTP Version HTTP/1.1
HTTPS ✔ Available
IP Address 192.0.78.229
Server Software nginx
CDN CDN detected (Server-Timing)
Compression gzip
🔒 🟡 Mixed Content (1 HTTP resources) The page is served over HTTPS but loads 1 resource(s) over HTTP. This may be blocked in modern browsers.
🕐 🟡 Slow Response (1563 ms) Response time exceeds 1 second. Consider optimizing the server or using caching.
ℹ 🔵 Missing Content Security Policy CSP is not configured. It helps prevent XSS attacks and content injection.
ℹ 🔵 Missing X-Frame-Options The site can be embedded in iframes by third parties (clickjacking risk).
Performance
| DNS Lookup | 6.3 ms |
| TCP Connect | 7.5 ms |
| TLS Handshake | 3.8 ms |
| Time To First Byte (TTFB) | 1503.5 ms |
| Content Download | 59.2 ms |
| Total Response Time | 1562.7 ms |
DNS Lookup 6.3 ms
TCP Connect 7.5 ms
TLS Handshake 3.8 ms
Time To First Byte (TTFB) 1503.5 ms
Content Download 59.2 ms
Total Response Time 1562.7 ms
Security
| HTTPS | ✔ Enabled |
| HSTS | ✔ max-age=31536000 |
| CSP | ⚠ Not configured |
| X-Frame-Options | ⚠ Not configured |
| X-Content-Type-Options | ⚠ Not configured |
| Permissions Policy | ✔ Configured |
| HTTP/2 | ⚠ HTTP/1.1 |
HTTPS ✔ Enabled
HSTS ✔ max-age=31536000
CSP ⚠ Not configured
X-Frame-Options ⚠ Not configured
X-Content-Type-Options ⚠ Not configured
Permissions Policy ✔ Configured
HTTP/2 ⚠ HTTP/1.1
SEO Quick Check
| Title | Holalola – Gift Shop |
| Canonical | https://holalolashop.com/ |
| Robots Meta | max-image-preview:large |
Title Holalola – Gift Shop
Canonical https://holalolashop.com/
Robots Meta max-image-preview:large
Detected Technologies
| Technology | WordPress WooCommerce jQuery Google Analytics Google Tag Manager Cloudflare Nginx PHP Node.js |
Technology WordPress WooCommerce jQuery Google Analytics Google Tag Manager Cloudflare Nginx PHP Node.js
HTTP Headers
| Server
| nginx |
| Date
| Wed, 19 Aug 2026 23:12:13 GMT |
| Content-type
| text/html; charset=UTF-8 |
| Strict-transport-security
| max-age=31536000 |
| Vary
| accept, content-type, cookie |
| X-hacker
| Want root? Visit join.a8c.com and mention this header. |
| Host-header
| WordPress.com |
| Permissions-policy
| private-state-token-redemption=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com"), private-state-token-issuance=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com") |
| Link
| ; rel=shortlink |
| Last-modified
| Wed, 19 Aug 2026 23:12:13 GMT |
| Cache-control
| max-age=300, must-revalidate |
| X-nananana
| Batcache-Set |
| Content-encoding
| gzip |
| X-ac
| 17.cdg _atomic_ams MISS |
| Alt-svc
| clear |
| Server-timing
| a8c-cdn, dc;desc=cdg, cache;desc=MISS;dur=1491.0 |
Meta Tags
| Viewport | width=device-width, initial-scale=1, minimum-scale=1, maximum-scale=1, user-scalable=no |
| Robots | max-image-preview:large |
| Generator | Powered by WPBakery Page Builder - drag and drop page builder for WordPress. |
| Google-site-verification | 5r15dfnmLg2yAuCrpzu-5k8nPTEGJ7b_nmJvTWsDzH8 |
| Google-adsense-platform-account | ca-host-pub-2644536267352236 |
| Google-adsense-platform-domain | sitekit.withgoogle.com |
| Msapplication-TileImage |  |
Server nginx
Date Wed, 19 Aug 2026 23:12:13 GMT
Content-type text/html; charset=UTF-8
Strict-transport-security max-age=31536000
Vary accept, content-type, cookie
X-hacker Want root? Visit join.a8c.com and mention this header.
Host-header WordPress.com
Permissions-policy private-state-token-redemption=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com"), private-state-token-issuance=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com")
Link ; rel=shortlink
Last-modified Wed, 19 Aug 2026 23:12:13 GMT
Cache-control max-age=300, must-revalidate
X-nananana Batcache-Set
Content-encoding gzip
X-ac 17.cdg _atomic_ams MISS
Alt-svc clear
Server-timing a8c-cdn, dc;desc=cdg, cache;desc=MISS;dur=1491.0