a2pasos.es
HTML metadata
Technology
- Server
- nginx
- CMS
- Gatsby
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (6)
- unpkg.com×5
- cdn.jsdelivr.net×4
- site-assets.fontawesome.com×1
- www.google.com×1
- www.googletagmanager.com×1
- www.svgrepo.com×1
Social
Contact
DNS records live
- NS
-
- ns1072.ui-dns.org
- ns1081.ui-dns.biz
- ns1114.ui-dns.com
- ns1117.ui-dns.de
- MX
-
- 10 mx00.ionos.es
- 10 mx01.ionos.es
- TXT
-
google-site-verification=daMrDWLE3wJs2S7-uXOhUi-pWr-2X6JLG6bZ-FazA6U
Email authentication partial
- SPF
-
v=spf1 include:_spf-eu.ionos.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none;policy: none (monitoring only) - DKIM
- no key found at common selectors
Certificate (current)
E7
Expires in 49 days
HTTP security headers
- present
-
- content-security-policy
- x-content-type-options
- referrer-policy
- cross-origin-opener-policy
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- missing frame protection
- missing Permissions Policy
Header values
- referrer-policy
same-origin- x-content-type-options
nosniff- content-security-policy
script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.jsdelivr.net https://unpkg.com https://www.google.com https://www.gstatic.com https://www.googletagmanager.com; font-src 'self' https://fonts.gstatic.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://site-assets.fontawesome.com; frame-src 'self' https://www.google.com; frame-ancestors 'self' https://elchecapitalmediterranea.com https://www.elchecapitalmediterranea.com https://elchedeporte.appeurowebmedia.es; img-src 'self' data: blob: https://www.svgrepo.com https://cdn.jsdelivr.net https://www.google.com https://www.gstatic.com https://site-assets.fontawesome.com https://a.basemaps.cartocdn.com https://b.basemaps.cartocdn.com https://c.basemaps.cartocdn.com https://unpkg.com; connect-src 'self' https://unpkg.com https://a.basemaps.cartocdn.com https://b.basemaps.cartocdn.com https://c.basemaps.cartocdn.com https://cdn.jsdelivr.net; default-src 'self'; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net h- cross-origin-opener-policy
same-origin
Links to (4)
- elche.es×2
- gva.es×2
- instagram.com×2
- linkedin.com×2