bugbop.com
HTML metadata
Technology
- CDN
- Cloudflare
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (4)
- cdnjs.cloudflare.com×3
- analytics.ahrefs.com×1
- challenges.cloudflare.com×1
- www.googletagmanager.com×1
Social
Registration
- Registrar
- NameCheap, Inc.
- Created
- 2025-01-04
- Expires
- 2027-01-04 230 days left
- Updated
- 2025-12-06
- Name servers
-
- keanu.ns.cloudflare.com
- lilyana.ns.cloudflare.com
DNS records live
- NS
-
- keanu.ns.cloudflare.com
- lilyana.ns.cloudflare.com
- MX
-
- 1 smtp.google.com
- TXT
-
google-site-verification=kAysAHBgsiq15I1VHsyoTiNrOFFkNgpmclv2HAiHrGY
Email authentication strong
- SPF
-
v=spf1 include:mailgun.org include:_spf.google.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; pct=100; fo=1; ri=3600; rua=mailto:ea110ff4@dmarc.mailgun.org,mailto:ec5e44c1@inbox.ondmarc.com; ruf=mailto:ea110ff4@dmarc.mailgun.org,mailto:ec5e44c1@inbox.ondmarc.com;policy: quarantine - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAviRFG6Z8kYT9jEZZfEy+KCKzX8sVh64UgDesCfUZ+VaPqt1izO9734gxFfZIvPMbusub6SlQHExjMV…
selectors probed - google:
Certificate (current)
WE1
Expires in 65 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' https:; font-src 'self' https: data:; img-src 'self' https: data:; object-src 'none'; script-src 'self' https: 'unsafe-eval' 'unsafe-inline' *.cloudflare.com www.googletagmanager.com; style-src 'self' https: 'unsafe-inline' *.cloudflare.com; connect-src 'self' https:; form-action 'self'; frame-ancestors 'none'; base-uri 'self'; report-uri /csp-violation-report-endpoint- strict-transport-security
max-age=2592000; includeSubDomains; preload- cross-origin-opener-policy
same-origin-allow-popups- cross-origin-embedder-policy
unsafe-none
Links to (4)
- calendly.com×2
- linkedin.com×2
- x.com×2
- bsky.app×2