avescan.io
HTML metadata
Technology
- Server
- nginx
- CMS
- Next.js
- JS framework
- Next.js
- Fonts
-
- Google Fonts
Third-party hosts loaded (1)
- fonts.gstatic.com×1
Social
DNS records live
- NS
-
- dns1.namecheaphosting.com
- dns2.namecheaphosting.com
- MX
-
- 5 mx1-hosting.jellyfish.systems
Email authentication weak
- SPF
-
v=spf1 +a +mx +ip4:185.61.154.212 include:spf.web-hosting.com ~allsoftfail (~all) - DMARC
- not published
- DKIM
-
- default:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwZXJpj3s78BrSMMLOAsLFsTAPeoHVE6wpqchqnpmhMLZPAev8N9xomKjMHDz+9cJ845ueC4+kjbwVK…
selectors probed - default:
Certificate (current)
E8
Expires in 84 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- cross-origin-opener-policy
- findings
-
- missing HSTS
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self';connect-src 'self' *.avescan.io avescan.io https://avescan.io wss://avescan.io http://qtm.avescoin.io:8081 https://infragrid.v.network raw.githubusercontent.com coinzilla.com *.coinzilla.com https://request-global.czilladx.com *.slise.xyz api.hypelab.com *.ixncdn.com v1.getittech.io ipapi.co fonts.gstatic.com sentry.io *.sentry.io;script-src 'self' *.avescan.io avescan.io 'sha256-e7MRMmTzLsLQvIy1iizO1lXf7VWYoQ6ysj5fuUzvRwE=' coinzillatag.com servedbyadbutler.com 'sha256-wMOeDjJaOTjCfNjluteV+tSqHW547T89sgxd8W6tQJM=' 'sha256-47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=' *.slise.xyz https://api.hypelab.com d1q98dzwj6s2rb.cloudfront.net static.cloudflareinsights.com blob: https://cdn.jsdelivr.net/npm/monaco-editor@0.33.0/min/vs/loader.js https://cdn.jsdelivr.net/npm/monaco-editor@0.33.0/min/vs/editor/editor.main.js https://cdn.jsdelivr.net/npm/monaco-editor@0.33.0/min/vs/editor/editor.main.nls.js https://cdn.jsdelivr.net/npm/monaco-editor@0.33.0/min/vs/basic-languages/so- cross-origin-opener-policy
same-origin
Links to (4)
- twitter.com×1
- github.com×1
- canny.io×1
- blockscout.com×1