cappacare.com
HTML metadata
Technology
- Server
- Heroku
- CMS
- Gatsby
- Fonts
-
- Google Fonts
Third-party hosts loaded (6)
- sharetribe-assets.imgix.net×4
- fonts.googleapis.com×2
- cdnjs.cloudflare.com×1
- fonts.gstatic.com×1
- js.stripe.com×1
- maps.googleapis.com×1
Social
Registration
- Registrar
- NameCheap, Inc.
- Created
- 2025-03-20
- Expires
- 2028-03-20 671 days left
- Updated
- 2025-03-20
- Name servers
-
- dns1.registrar-servers.com
- dns2.registrar-servers.com
DNS records live
- NS
-
- dns1.registrar-servers.com
- dns2.registrar-servers.com
- MX
-
- 10 eforward1.registrar-servers.com
- 10 eforward2.registrar-servers.com
- 10 eforward3.registrar-servers.com
- 15 eforward4.registrar-servers.com
- 20 eforward5.registrar-servers.com
Email authentication weak
- SPF
-
v=spf1 include:spf.efwd.registrar-servers.com ~allsoftfail (~all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 30 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy-report-only
- x-frame-options
- x-content-type-options
- referrer-policy
- cross-origin-opener-policy
- cross-origin-resource-policy
- findings
-
- missing Content Security Policy
- missing Permissions Policy
Header values
- referrer-policy
origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- strict-transport-security
max-age=31536000; includeSubDomains- cross-origin-opener-policy
same-origin- cross-origin-resource-policy
same-origin- content-security-policy-report-only
report-uri /csp-report;base-uri 'self';default-src 'self';child-src blob:;connect-src 'self' https://flex-api.sharetribe.com undefined *.st-api.com maps.googleapis.com places.googleapis.com *.tiles.mapbox.com api.mapbox.com events.mapbox.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.g.doubleclick.net *.google.com plausible.io *.plausible.io fonts.googleapis.com sentry.io *.sentry.io *.stripe.com;font-src 'self' data: assets-sharetribecom.sharetribe.com fonts.gstatic.com;form-action 'self';frame-src 'self' *.stripe.com *.youtube-nocookie.com https://bid.g.doubleclick.net https://td.doubleclick.net;img-src 'self' data: blob: *.imgix.net sharetribe.imgix.net picsum.photos *.picsum.photos api.mapbox.com maps.googleapis.com *.gstatic.com *.googleapis.com *.ggpht.com *.giphy.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.g.doubleclick.net *.google.com google.com *.ytimg.com *.stripe.com;script-src 'self' 'nonce-d543f425f19955bb94c1af5b
Links to (4)
- facebook.com×2
- instagram.com×2
- pinterest.com×2
- x.com×2