danielfiene.com
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- WordPress
- Analytics
-
- Cloudflare Insights
- Social widgets
-
- Twitter Widget
Third-party hosts loaded (16)
- app.ecwid.com×2
- www.google.com×2
- 0.gravatar.com×1
- 1.gravatar.com×1
- 2.gravatar.com×1
- d1oxsl77a1kjht.cloudfront.net×1
- d1q3axnfhmyveb.cloudfront.net×1
- dqzrr9k4bjpzk.cloudfront.net×1
- ecomm.events×1
- platform.twitter.com×1
- s0.wp.com×1
- secure.gravatar.com×1
- static.cloudflareinsights.com×1
- stats.wp.com×1
- v0.wordpress.com×1
- widgets.wp.com×1
Contact
- Address
- rd Threads 2025
Registration
- Registrar
- DropCatch.com 584 LLC
- Created
- 2025-02-23
- Expires
- 2027-02-23 280 days left
- Updated
- 2026-01-24
- Name servers
-
- dean.ns.cloudflare.com
- katelyn.ns.cloudflare.com
DNS records live
- NS
-
- dean.ns.cloudflare.com
- katelyn.ns.cloudflare.com
- MX
-
- 41 route3.mx.cloudflare.net
- 78 route1.mx.cloudflare.net
- 79 route2.mx.cloudflare.net
Email authentication weak
- SPF
-
v=spf1 include:_spf.mx.cloudflare.net ~allsoftfail (~all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
WE1
Expires in 66 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(*),midi=(*),sync-xhr=(*),microphone=(*),camera=(*),magnetometer=(*),gyroscope=(*),fullscreen=(*),payment=(*)- x-content-type-options
nosniff- content-security-policy
default-src * gap://ready file:; worker-src blob:; child-src blob: gap:; style-src * 'unsafe-inline'; script-src * 'unsafe-inline' 'unsafe-eval' blob:; img-src * 'self' data: blob: cdvfile:; connect-src * 'unsafe-inline'; font-src 'self' data: *; frame-src *;media-src * blob:; frame-ancestors 'self';- strict-transport-security
max-age=31536000;includeSubdomains; preload