Technical Information
| HTTP Status Code | 200 |
| HTTP Version | HTTP/1.1 |
| HTTPS | ✔ Available |
| IP Address | 13.227.231.86 |
| Server Software | nginx + Phusion Passenger |
| Compression | gzip |
|
🔒 🟡 Mixed Content (5 HTTP resources) | The page is served over HTTPS but loads 5 resource(s) over HTTP. This may be blocked in modern browsers. |
|
🕐 🟡 Slow Response (1843 ms) | Response time exceeds 1 second. Consider optimizing the server or using caching. |
|
ℹ 🔵 Missing Content Security Policy | CSP is not configured. It helps prevent XSS attacks and content injection. |
HTTP Status Code 200
HTTP Version HTTP/1.1
HTTPS ✔ Available
IP Address 13.227.231.86
Server Software nginx + Phusion Passenger
Compression gzip
🔒 🟡 Mixed Content (5 HTTP resources) The page is served over HTTPS but loads 5 resource(s) over HTTP. This may be blocked in modern browsers.
🕐 🟡 Slow Response (1843 ms) Response time exceeds 1 second. Consider optimizing the server or using caching.
ℹ 🔵 Missing Content Security Policy CSP is not configured. It helps prevent XSS attacks and content injection.
Redirect Chain
| # | URL | HTTP Status Code | Status |
| 1 | https://patientslikeme.com:443 | 301 | HTTP/2 301 |
| 2 | https://www.patientslikeme.com:443/ | 200 | HTTP/2 200 |
#1 URL https://patientslikeme.com:443
HTTP Status Code 301
Status HTTP/2 301
#2 URL https://www.patientslikeme.com:443/
HTTP Status Code 200
Status HTTP/2 200
Performance
| DNS Lookup | 25.6 ms |
| TCP Connect | 121.2 ms |
| TLS Handshake | 98.8 ms |
| Time To First Byte (TTFB) | 1650.9 ms |
| Content Download | 192 ms |
| Total Response Time | 1842.9 ms |
DNS Lookup 25.6 ms
TCP Connect 121.2 ms
TLS Handshake 98.8 ms
Time To First Byte (TTFB) 1650.9 ms
Content Download 192 ms
Total Response Time 1842.9 ms
Security
| HTTPS | ✔ Enabled |
| HSTS | ✔ max-age=31536000; includeSubDomains |
| CSP | ⚠ Not configured |
| X-Frame-Options | ✔ SAMEORIGIN |
| X-Content-Type-Options | ✔ nosniff |
| Referrer Policy | strict-origin-when-cross-origin |
| Permissions Policy | ✔ Configured |
| HTTP/2 | ⚠ HTTP/1.1 |
HTTPS ✔ Enabled
HSTS ✔ max-age=31536000; includeSubDomains
CSP ⚠ Not configured
X-Frame-Options ✔ SAMEORIGIN
X-Content-Type-Options ✔ nosniff
Referrer Policy strict-origin-when-cross-origin
Permissions Policy ✔ Configured
HTTP/2 ⚠ HTTP/1.1
SEO Quick Check
| Title | Live better, together! | PatientsLikeMe |
Title Live better, together! | PatientsLikeMe
Detected Technologies
| Technology | Google Analytics Google Tag Manager Nginx |
Technology Google Analytics Google Tag Manager Nginx
HTTP Headers
| Date
| Fri, 24 Jul 2026 05:53:02 GMT |
| Content-type
| text/html; charset=utf-8 |
| Status
| 200 OK |
| Cache-control
| max-age=0, private, must-revalidate |
| Permissions-policy
| camera=(), microphone=(), geolocation=() |
| Referrer-policy
| strict-origin-when-cross-origin |
| X-permitted-cross-domain-policies
| none |
| X-xss-protection
| 1; mode=block |
| X-request-id
| 5c6b9aeb-cca1-4014-a4b6-e232b24b3a2c |
| Content-security-policy-report-only
| default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.google-analytics.com https://www.googletagmanager.com https://cdn.appcues.com https://cdn.cookielaw.org https://js.rollbar.com; style-src 'self' 'unsafe-inline' https://cdn.cookielaw.org; img-src 'self' data: https:; font-src 'self' data: https://dy82vckl8b34w.cloudfront.net; connect-src 'self' https://api.patientslikeme.com https://www.google-analytics.com https://api.rollbar.com; object-src 'none'; frame-ancestors 'self' |
| Etag
| W/"4200e2093e8ad1af1dab9a11ea700986" |
| X-runtime
| 1.310871 |
| Set-cookie
| _session_id=eedbc842aa1583945f4142413454bc27; path=/; expires=Fri, 21 Aug 2026 05:53:02 GMT; secure; HttpOnly |
| X-powered-by
| Phusion Passenger |
| Server
| nginx + Phusion Passenger |
| Content-encoding
| gzip |
| Strict-transport-security
| max-age=31536000; includeSubDomains |
| X-content-type-options
| nosniff |
| X-frame-options
| SAMEORIGIN |
Meta Tags
| Google-site-verification | 1HDSP9OrOJcVQkkXRJOLPupdmvKIuwBZeeMy8ds_VBA |
| Csrf-param | authenticity_token |
| Csrf-token | yNrI0O/HHFbUhBX8zvzP9W10nczS4p79iSf88HfBuUZ2pl87rM088UY/VxQ0AyteRjR28923lPrnW3fzKgcmjQ== |
Date Fri, 24 Jul 2026 05:53:02 GMT
Content-type text/html; charset=utf-8
Status 200 OK
Cache-control max-age=0, private, must-revalidate
Permissions-policy camera=(), microphone=(), geolocation=()
Referrer-policy strict-origin-when-cross-origin
X-permitted-cross-domain-policies none
X-xss-protection 1; mode=block
X-request-id 5c6b9aeb-cca1-4014-a4b6-e232b24b3a2c
Content-security-policy-report-only default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.google-analytics.com https://www.googletagmanager.com https://cdn.appcues.com https://cdn.cookielaw.org https://js.rollbar.com; style-src 'self' 'unsafe-inline' https://cdn.cookielaw.org; img-src 'self' data: https:; font-src 'self' data: https://dy82vckl8b34w.cloudfront.net; connect-src 'self' https://api.patientslikeme.com https://www.google-analytics.com https://api.rollbar.com; object-src 'none'; frame-ancestors 'self'
Etag W/"4200e2093e8ad1af1dab9a11ea700986"
X-runtime 1.310871
Set-cookie _session_id=eedbc842aa1583945f4142413454bc27; path=/; expires=Fri, 21 Aug 2026 05:53:02 GMT; secure; HttpOnly
X-powered-by Phusion Passenger
Server nginx + Phusion Passenger
Content-encoding gzip
Strict-transport-security max-age=31536000; includeSubDomains
X-content-type-options nosniff
X-frame-options SAMEORIGIN