cebre.cz
HTML metadata
Technology
- CMS
- WordPress
- jQuery
- 1.12.4 known XSS (<3.5)
- Analytics
-
- Google Tag Manager
- Social widgets
-
- Twitter Widget
Third-party hosts loaded (4)
- fonts.cdnfonts.com×1
- maps.googleapis.com×1
- platform.twitter.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
Registration
- Registrar
- REG-MEDIA4WEB
- Created
- 2002-03-17
- Expires
- 2027-03-15 287 days left
- Updated
- 2006-08-04
- Name servers
-
- dns.viwefix.cz
- sns.viwefix.cz
DNS records live
- NS
-
- dns.nethost.cz
- sns.nethost.sk
- MX
-
- 0 cts3.czechtrade.cz
- Verified for
-
- Microsoft 365
Email authentication weak
- SPF
-
v=spf1 +a +mx +include:servers.mcsv.net +include:_spf.google.com +include:server23.cyberfox.cz +include:spf.protection.outlook.com ~allsoftfail (~all) - DMARC
- not published
- DKIM
-
- default:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDJ+mG1HVr2nnmFtwZ0i86YtdfGXzeoPffdjF8LPxxNhqOByLPcP9nQzoOUrHdILU73IK+vKt6awvUIvOcqqS… - k1:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUo…
selectors probed - default:
Certificate (current)
R13
Expires in 18 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
- weak content type protection
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin, strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN, SAMEORIGIN- x-content-type-options
nosniff, nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.avvo.com *.bbb.org *.doubleclick.net *.facebook.net *.google-analytics.com *.google.com *.google.cz *.googleadservices.com *.googlesyndication.com *.googletagmanager.com *.gravatar.com *.gstatic.com *.newrelic.com *.nr-data.net *.olark.com *.twitter.com *.twimg.com *.wp.com *.youtube.com *.vimeo.com *.ytimg.com *.cloudflare.com *.amazonaws.com *.googleapis.com *.issuu.com; style-src * data: 'unsafe-inline'; img-src * data:;media-src * blob:; font-src * data: 'unsafe-inline'; connect-src 'self' *.akismet.com *.bbb.org *.google.com *.google.cz *.googlesyndication.com *.gstatic.com *.facebook.com *.twitter.com *.olark.com *.youtube.com *.vimeo.com akismet.com *.issuu.com; object-src 'none'; child-src 'self' *.avvo.com *.bbb.org *.doubleclick.net *.facebook.com *.googletagmanager.com *.olark.com *.wp.com *.youtube.com *.vimeo.com akismet.com example.com *.issuu.com; frame-src 'self' *.avvo.com *.bbb.org *.doubleclick.net- strict-transport-security
max-age=31536000; includeSubDomains; preload, max-age=31536000; includeSubDomains; preload
Links to (9)
- campaign-archive.com×1
- cookielaw.org×1
- cyberfox.cz×1
- czechtrade.cz×1
- komora.cz×1
- kzps.cz×1
- mpo.cz×1
- spcr.cz×1
- twitter.com×1
Linked from (1)
- kzps.cz×1