1wp.io

.io crawl

First seen 2026-05-27 · Last seen 2026-05-31 · ok HTTP/1.1 200 248 ms crawled 2026-05-30

US · 172.67.152.137 · AS13335 Cloudflare, Inc.

Reputation 92/100 weak subdomain policy

Classifying

HTML metadata

Title
1WP / Premium WordPress Website Developement
Description
Ein sicheres, schnelles und flexibles Framework für dein Business. Skalierbar vom Onepager bis zur eCommerce Plattform. Webentwicklung auf neuem Niveau.
Language
de
Generator
Elementor 3.35.7; features: e_font_icon_svg, additional_custom_breakpoints; settings: css_print_method-external, google_font-enabled, font_display-auto
Canonical
https://1wp.io/

Open Graph

url
https://1wp.io
title
1WP / Premium WordPress Website Developement
locale
de_DE
site name
1WP / Premium WordPress Website Developement
description
Ein sicheres, schnelles und flexibles Framework für dein Business. Skalierbar vom Onepager bis zur eCommerce Plattform. Webentwicklung auf neuem Niveau.

Technology

CDN
Cloudflare
PHP
8.2.31 security-only

Third-party hosts loaded (1)

  • gmpg.org×1

Social

Contact

Phone

DNS records live

NS
  • adele.ns.cloudflare.com
  • fonzie.ns.cloudflare.com
MX
  • 0 1wp-io.mail.protection.outlook.com
Verified for
  • Microsoft 365

Email authentication strong

SPF
v=spf1 +a +mx include:spf.1wp.cloud -all
strict (-all)
DMARC
v=DMARC1; p=quarantine; sp=none; rua=mailto:mailmaster@1wp.io; adkim=r; aspf=r;
policy: quarantine · sp=none
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCXR7nr18Ajzebej4faROWiPaJZGeGM9LatMLRGC9mOwV1RUAOeMLpKcn61crahNcSG2uySQHdL983BUu9I9y…
  • selector2: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC5t2Cb+Uuh4MOsrWz5CEtnd4AeqQXVw2Vu/cjhrKv1l3rPdiBK3aNPVykMVWKCjHYGWn4IiZLTget9xEX/MP…
selectors probed

Certificate (current)

E7
from 2026-05-02 to 2026-07-31
Expires in 60 days

HTTP security headers

Header hygiene 65/100 Checked live page: https://1wp.io/

present
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • missing HSTS
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src 'self' data: blob: https: 'unsafe-inline' 'unsafe-eval'; img-src 'self' https: data: http://*.zemez.io; connect-src 'self' data: https:; frame-src 'self' https:; form-action 'self' https:; frame-ancestors 'self'; font-src 'self' https: data:; worker-src 'self' blob:;

Links to (4)

Linked from (2)