campofriohealthcare.es
HTML metadata
Technology
- CMS
- Drupal
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (1)
- www.googletagmanager.com×1
Contact
- Phone
DNS records live
- NS
-
- ns-162-b.gandi.net
- ns-179-c.gandi.net
- ns-218-a.gandi.net
- TXT
-
v=spf1 include:spf.campofriofg.com include:8009626.spf01.hubspotemail.net -allr212vk8q83lq9a6016o9dpbv34
- Verified for
-
- GlobalSign
Certificate (current)
GlobalSign Atlas R3 DV TLS CA 2026 Q1
Expires in 35 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- content-security-policy-report-only
- x-frame-options
- x-content-type-options
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
Header values
- x-frame-options
SAMEORIGIN- permissions-policy
camera=(), microphone=(), geolocation=(), browsing-topics=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'unsafe-inline' 'unsafe-eval' 'self' *.clarity.ms https://cc.cdn.civiccomputing.com/9/cookieControl-9.x.min.js https://connect.facebook.net https://cwcentribot.centribal.com https://googleads.g.doubleclick.net https://js.hs-analytics.net https://js.hs-banner.com https://js.hs-scripts.com https://js.hsadspixel.net https://js.hscollectedforms.net/collectedforms.js https://js.hscta.net/cta/current.js https://js.hsforms.net/forms/v2.js https://kit.fontawesome.com https://pagead2.googlesyndication.com https://www.google.com/recaptcha/api.js https://www.googleadservices.com https://www.googletagmanager.com https://www.gstatic.com; style-src 'unsafe-inline' 'self' https://fonts.sandbox.google.com; object-src 'none'; base-uri 'self'; connect-src 'self' *.clarity.ms https://api.hubapi.com https://apikeys.civiccomputing.com https://campofriohealthcare-pro.myshopify.com https://clapi.civiccomputing.com https://forms.hscollectedforms.net https://forms.hsforms.com htt- strict-transport-security
max-age=31536000; includeSubDomains, max-age=31536000; includeSubDomains; preload;- content-security-policy-report-only
default-src 'self' 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' data: blob: ; form-action 'none' ; frame-ancestors 'self' ; script-src 'unsafe-eval' 'unsafe-hashes' 'report-sample'; report-uri /csp_report