agendamientojavesalud.com.co
HTML metadata
Technology
- CMS
- Ghost
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (4)
- fonts.googleapis.com×3
- fonts.gstatic.com×1
- www.facebook.com×1
- www.googletagmanager.com×1
DNS records live
- NS
-
- ns09.domaincontrol.com
- ns10.domaincontrol.com
- TXT
-
dk31su6pib70pbp2b6vgmavdc1
Email authentication no MX
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
Go Daddy Secure Certificate Authority - G2
Expires in 212 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
Header values
- referrer-policy
no-referrer- permissions-policy
accelerometer=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=()- x-content-type-options
nosniff- content-security-policy
default-src * 'self' 'unsafe-inline' 'unsafe-eval' cdn.kustomerapp.com ; script-src 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' *.azurewebsites.net:* https://connect.facebook.net:* https://cdn.userway.org:* https://*.googleapis.com https://*.gstatic.com *.google.com https://*.ggpht.com *.googleusercontent.com blob: https://connect.facebook.net/en_US/fbevents.js https://script.hotjar.com:* https://cdn.gtranslate.net:* https://static.hotjar.com:* https://www.googletagmanager.com/gtag/js https://ajax.googleapis.com/ajax/libs/jquery/2.2.4/jquery.min.js https://rawgit.com/RobinHerbots/Inputmask/4.x/dist/jquery.inputmask.bundle.js https://wchat.freshchat.com/js/widget.js https://ajax.googleapis.com/ajax/libs/jquery/1.11.1/jquery.min.js https://code.jquery.com/ui/1.11.0/jquery-ui.js https://rawgit.com/RobinHerbots/Inputmask/4.x/- strict-transport-security
max-age=31536000; includeSubDomains- cross-origin-opener-policy
*- cross-origin-embedder-policy
*- cross-origin-resource-policy
*
agendamientojavesalud.com.co