bodytech.com.co
HTML metadata
Technology
- Server
- nginx
- CMS
- Next.js
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (3)
- bodytech.imgix.net×2
- lavchat-user-styles.lavenirapps.co×1
- www.googletagmanager.com×1
DNS records live
- NS
-
- ns-1482.awsdns-57.org
- ns-1542.awsdns-00.co.uk
- ns-6.awsdns-00.com
- ns-609.awsdns-12.net
- TXT
-
Show 8 TXT records
facebook-domain-verification=jald8m3nqz0bme472g1f4kilpr6qtzgoogle-site-verification=2KClSYlypKEJupMbg8c6HmhXFTSc7j9BwZyhaCCe6WUgoogle-site-verification=HJifSHIYzjiAqo3aTMwqr0shELNcikTYYtbw6HU8QtQgoogle-site-verification=NAvEevSmPG8we-hFhvX242NlBCf4PoeRriI-SeZfC8k.google-site-verification=V2UKLOpa3Y2aN_qjqpl4rrsMAQbTe-LMkqO8Hwhij1kgoogle-site-verification=Zuw1gNEkabqWTkiRj6Dh544god6-vHommHxwGBPUpm4google-site-verification=fCgwGBd1TEt9CjrvV_poXTdchKANvdtU1XiM-DZvIRsgoogle-site-verification=rC7BiGTl2F908nxYr5w8wFR4nMJlV94aq2WkoDs0_Ms
Certificate (current)
Amazon RSA 2048 M04
Expires in 294 days
HTTP security headers
- present
-
- content-security-policy
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- content-security-policy
script-src 'self' https://*.useinsider.com https://*.api.useinsider.com https://www.google.com https://www.gstatic.com https://www.google-analytics.com https://www.googletagmanager.com https://googleads.g.doubleclick.net https://static.hotjar.com https://dev.visualwebsiteoptimizer.com http://l.getsitecontrol.com https://connect.facebook.net https://analytics.tiktok.com 'unsafe-inline' 'unsafe-eval';