bing-ventures.com
HTML metadata
Technology
- CDN
- Cloudflare
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (5)
- bin.bb-os.com×10
- www.googletagmanager.com×2
- api-app.qq-os.com×1
- bb-client-new.log-global.aliyuncs.com×1
- static-app.bb-os.com×1
Social
Registration
- Registrar
- Name.com, Inc.
- Created
- 2021-07-24
- Expires
- 2026-07-24 66 days left
- Updated
- 2023-07-03
- Name servers
-
- amit.ns.cloudflare.com
- melissa.ns.cloudflare.com
DNS records live
- NS
-
- amit.ns.cloudflare.com
- melissa.ns.cloudflare.com
- MX
-
- 10 alt1.aspmx.l.google.com
- 10 alt2.aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 aspmx.l.google.com
- TXT
-
ca3-63c9f97fd2354ff0905fcb3ec59c15fa
Certificate (current)
E8
Expires in 21 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' blob: *.line-scdn.net;img-src https: *.google-analytics.com 'self' * data: blob:;style-src 'self' https: 'unsafe-inline';script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: *.appsflyer.com *.guance.com *.teststar.cc *.bb-os.com *.webpushs.com *.legendtrading.com *.sendpulse.com *.bing.com cdn.jsdelivr.net *.crowdin.com *.bingx.com *.googletagmanager.com static.zdassets.com *.google-analytics.com ajax.cloudflare.com *.geetest.com *.qbox.me *.zopim.com *.tradingview.com *.twitter.com *.recaptcha.net *.google.com appleid.cdn-apple.com *.facebook.net *.facebook.com *.tiktok.com *.gstatic.com *.doubleclick.net *.googleadservices.com *.volccdn.com *.ibytedtos.com fpnpmcdn.net fpcdn.io *.prdredir.com *.geevisit.com *.mql5.com *.taboola.com *.ads-twitter.com *.yandex.ru adscool.net *.zendesk.com *.botlabpro.com *.netshunt.com *.botion.com storage.googleapis.com *.clarity.ms *.houtai.io *.line-scdn.net;connect-src 'self' 'unsafe-inline' * data: blob: *.fptls.com api.fpjs.io- strict-transport-security
max-age=31536000; includeSubDomains; preload
Links to (4)
- linkedin.com×2
- medium.com×2
- t.me×2
- twitter.com×2