championtimber.com
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Gatsby
- PHP
- 8.3.26 security-only
- Stack
- PHP
- Analytics
-
- Cloudflare Insights
- Google Tag Manager
- Ads
-
- Meta Pixel
- Fonts
-
- Google Fonts
Third-party hosts loaded (14)
- cdn.icomoon.io×5
- fonts.googleapis.com×3
- cdn.jsdelivr.net×1
- connect.facebook.net×1
- d1azc1qln24ryf.cloudfront.net×1
- fonts.gstatic.com×1
- invitejs.trustpilot.com×1
- js.stripe.com×1
- ls.dycdn.net×1
- maps.googleapis.com×1
- static.cloudflareinsights.com×1
- widget.trustpilot.com×1
- www.facebook.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
- Address
- 205 - 209 Burlington Road, KT3 4NB, Surrey, New Malden
Registration
- Registrar
- IONOS SE
- Created
- 2001-01-12
- Expires
- 2032-01-12 2051 days left
- Updated
- 2025-10-08
- Name servers
-
- cris.ns.cloudflare.com
- peaches.ns.cloudflare.com
DNS records live
- NS
-
- cris.ns.cloudflare.com
- peaches.ns.cloudflare.com
- MX
-
- 10 eu-smtp-inbound-1.mimecast.com
- 10 eu-smtp-inbound-2.mimecast.com
- TXT
-
0ed1fe018a4c57f4f03e9e4276b298f36c928f48a9
- Verified for
-
- GlobalSign
- Microsoft 365
Email authentication weak
- SPF
-
v=spf1 ip4:87.106.149.9 include:eu._netblocks.mimecast.com -allstrict (-all) - DMARC
- not published
- DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsJuhofQcv1o5stSCKBwqBKXsmzgUBmD1cCuTcMbNpklcxab9K02Mlhf04umAdQDuxT9Ib1vdQ4cTIgUxzj… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAs83duHJxwxxDmFIWg6o7Xs0E3cgSUK5x2t/xZimDFbzhR8+BIhIu+1IBq1VQA4PfDm5rvaJGe1x9dyBuLH…
selectors probed - s1:
Certificate (current)
GlobalSign GCC R6 AlphaSSL CA 2025
Expires in 177 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff, nosniff- content-security-policy
font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com www.paypalobjects.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.opayo.cloud cdn.icomoon.io storage.googleapis.com *.rsa3dsauth.co.uk static.lipscore.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.stripe.com *.stripe.network *.google.com *.sagepay.com *.opayo.eu.elavon.com *.opayo.cloud *.rsa3dsauth.co.uk creditc2.3debspay.boc.cn authentication-acs.marqeta.com clients.smartsecure.tsys.co.uk *.cmbchina.com *.edb.com 3ds.soldo.com acs.bpcprocessing.com *.americanexpress.com *.dkb.de *.modirum.co