comarch.ai
HTML metadata
Technology
- Server
- Apache
- CMS
- WordPress
- jQuery
- 3.7.1
- Analytics
-
- Google Tag Manager
- Ads
-
- Meta Pixel
- Fonts
-
- Google Fonts
Third-party hosts loaded (10)
- cdnjs.cloudflare.com×4
- unpkg.com×4
- fonts.googleapis.com×2
- js-eu1.hs-scripts.com×2
- www.googletagmanager.com×2
- connect.facebook.net×1
- fonts.gstatic.com×1
- js-eu1.hs-analytics.net×1
- js-eu1.hs-banner.com×1
- snap.licdn.com×1
Social
Contact
- Phone
Registration
- Registrar
- Ascio Technologies, Inc. Danmark - Filial af Ascio technologies, Inc. USA
- Created
- 2018-09-25
- Expires
- 2026-09-25 116 days left
- Updated
- 2025-09-07
- Name servers
-
- ns1.comarch.pl
- ns2.comarch.pl
- ns3.comarch.pl
DNS records live
- NS
-
- ns1.comarch.pl
- ns2.comarch.pl
- ns3.comarch.pl
- MX
-
- 1 manowce0.comarch.com
- 11 mx.comarch.com
- 111 manowce1.comarch.com
- Verified for
-
Email authentication weak
- SPF
-
v=spf1 ip4:91.227.213.0/27 include:_spf.google.com ~allsoftfail (~all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
RapidSSL TLS RSA CA G1
Expires in 253 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src * 'unsafe-inline' 'unsafe-eval' data: blob:; script-src * 'unsafe-inline' 'unsafe-eval' data: blob:; connect-src * 'unsafe-inline'; img-src * data: blob:; frame-src *; style-src * 'unsafe-inline';- strict-transport-security
max-age=31536000; includeSubDomains
Links to (5)
- youtube.com×1
- linkedin.com×1
- facebook.com×1
- comarch.pl×1
- comarch.com×1