digipage.app
HTML metadata
Technology
- Server
- nginx
Third-party hosts loaded (1)
- ladigitale.dev×1
DNS records live
- NS
-
- ns41.infomaniak.com
- ns42.infomaniak.com
Email authentication no MX
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R12
Expires in 30 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing content type protection
- missing Permissions Policy
Header values
- referrer-policy
same-origin- content-security-policy
default-src 'self' https: ws: data: 'none';script-src 'self' 'unsafe-inline' 'unsafe-eval' https://digipage.app/build/ https://digipage.app/js/ https://digipage.app/config https://gist.github.com/ https://vimeo.com/api/oembed.json https://umami.ladigitale.dev https://www.slideshare.net/api/oembed/2 'unsafe-inline' 'nonce-e996c144-cab4-42d5-98aa-605410cc37a3' 'sha256-81acLZNZISnyGYZrSuoYhpzwDTTxi7vC1YM4uNxqWaM=';style-src 'self' 'unsafe-inline' 'unsafe-eval' https://digipage.app/build/ https://digipage.app/css/ 'unsafe-inline' https://github.githubassets.com;img-src 'self' https: data: *;media-src 'self' data: *;frame-ancestors *;base-uri 'self';connect-src 'self' wss://digipage.app https://umami.ladigitale.dev;font-src 'self';manifest-src 'self';frame-src 'self' https://player.vimeo.com https://www.slideshare.net/slideshow/embed_code/key/ https://www.youtube.com *;object-src * *;form-action 'self'- strict-transport-security
max-age=31536000; includeSubDomains; preload